Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeLastPass for Safari
Findings · 3
+3 more findings locked
MEDIUM FINDINGS · 3
  1. 01Content script web-client-content-script.js runs on http://*/* and https://*/* (all_frames) and watches every page for login forms, fields, and submissions to drive autofill / save-prompt features.
  2. 02credentials-library.js is loaded into the page's MAIN world on every site and replaces navigator.credentials.create / navigator.credentials.get with LastPass-controlled wrappers that proxy WebAuthn / passkey requests through the extension.
  3. 03first-password-loggedin-detector.js probes whether the user is currently logged in to Google, Amazon, LinkedIn, Facebook, or Outlook by reading their cookies, querying their DOM, and (for LinkedIn) issuing a credentialed fetch to https://www.linkedin.com/feed; the boolean result is reported back to the extension to drive 'add your first password' onboarding.
+3 more findings locked
OTHER EXTENSIONS

Is LastPass for Safari safe?

Medium risk

No summary available.

LastPass US LPv4.151.5Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.lastpass.lastpassforsafari.safariext

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact