Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeInCognito
Findings · 3
+3 more findings locked
HIGH FINDINGS · 3
  1. 01Extension scrapes LinkedIn user profile PII (name, occupation, publicIdentifier, entityUrn) from page DOM and sends it to PostHog analytics
  2. 02Remote feature flags from PostHog control DOM selectors used by the extension, allowing server to change page scraping behavior
  3. 03Extension extracts user's primary email address from LinkedIn settings API and uses it as PostHog distinct_id for cross-session tracking
+3 more findings locked
OTHER EXTENSIONS

Is InCognito safe?

High risk

No summary available.

Tiny Unicornsv2.0.0Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026kencjkgapindpgehbgolojoocgpcepfk

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact