Am I Being Pwned? logoAm I Being Pwned?
Book a demo
Homeheylogin for Safari
Findings · 3
+3 more findings locked
MEDIUM FINDINGS · 3
  1. 01Content script on <all_urls> at document_start observes every login form submission (autosnatch) and forwards the entered username and cleartext password to the background script via runtime.sendMessage({type:'LoginSnatched'}); never leaves the extension but is the inherent risk surface of a password manager broker.
  2. 02Background script registers a blocking webRequest.onAuthRequired listener on every URL (*://*/*), allowing the extension to silently supply HTTP basic-auth username/password for any host where a stored login is tagged 'basic auth'.
  3. 03page.js (web-accessible, injected into every page via PageScriptManager) overrides navigator.credentials.get and navigator.credentials.create to intercept WebAuthn ceremonies, allowing the extension to handle passkey requests instead of the platform authenticator.
+3 more findings locked
OTHER EXTENSIONS

Is heylogin for Safari safe?

Low risk

No summary available.

heylogin GmbHv1.0.44Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026app.heylogin.webextension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact