Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeLoop8 Privacy Manager
Findings · 3
+1 more finding locked
LOW FINDINGS · 3
  1. 01Content-script on <all_urls> fetches a remote JSON model from extension.l8p8.com (unauthenticated, no integrity/signature) and compiles its embedded pattern strings via new RegExp(), so a compromise of that host can change form-field classification or trigger ReDoS in every page the extension runs on.
  2. 02Content-script on <all_urls> caches plaintext username and password values from any <form> on any site into in-memory tempCredentials (DetectionService.cacheCredential / stageCredential), to support save-credential prompts that route entries to the user's paired phone via native messaging or an https://api.l8p8.com/api/message relay.
  3. 03Sentry SDK is initialized inside the content-script that runs on <all_urls>, with a hardcoded DSN (ingest.sentry.io/4505752415633408); error events from any web page therefore include URL, user-agent and stack context that is sent to a third-party telemetry endpoint.
+1 more finding locked
OTHER EXTENSIONS

Is Loop8 Privacy Manager safe?

Low risk

No summary available.

L8P8, Incv0.2.46Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.l8p8.L8P8Safari.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact