Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeKeeper for Safari
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01User-triggered 'Report Autofill Issue' (KeeperFill Scout/Fixinator) sends full page HTML, screenshot (base64 PNG/JPEG), DOM tree, page URL, and load time of the active tab to fixinator.keeperpamlab.com when the user clicks the in-extension 'Report Autofill Issue' menu entry.
  2. 02Background fetches a 'patches' bundle (form-field detector overrides) from download.keepersecurity.com on startup; signature and MD5 are verified against headers x-amz-meta-checksum / x-amz-meta-signature / x-amz-meta-keyid before use, and patches are applied as labels (not executable code) to identified DOM trees.
  3. 03sso.js content script (matches: <all_urls>, run_at: document_start) registers a window.addEventListener('message', ...) handler that performs no event.origin check before dispatching on e.data.command === 'sso_login' or string-data branches; handler renders Keeper-styled 2FA/SSO UI into any pre-existing '.container' element on the page.
+2 more findings locked
OTHER EXTENSIONS

Is Keeper for Safari safe?

Low risk

No summary available.

Callpod Inc.v17.8.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.keepersecurity.safari.keeperfill.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact