Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeHouzz Save Button
Findings · 2
LOW FINDINGS · 2
  1. 01Content script injects a meta tag exposing extension-installed status (and Chrome extension ID) on every page whose document.domain matches the substring /houzz/, including unrelated third-party domains containing 'houzz'.
  2. 02window.postMessage handler in the all-sites content script uses loose substring matching (indexOf('houzz') / indexOf('localhost') / indexOf('houzzdev')) on event.origin to authorize a cookie-relay channel into the background page; spoofable origins like https://evilhouzz.com pass the check.
OTHER EXTENSIONS

Is Houzz Save Button safe?

Low risk

No summary available.

Houzz Inc.v1.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.houzz.houzzsavebutton.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact