Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeMimeo Photos: Printed Memories
Findings · 3
LOW FINDINGS · 3
  1. 01Embedded Mediaclip designer WebView loads Google Tag Manager container GTM-W9DZW56 from googletagmanager.com on every project edit, granting Mimeo the ability to inject arbitrary remote tracking scripts into the in-app design surface where users compose photo books, cards, calendars, and prints.
  2. 02Bundles Microsoft App Center Analytics + Crashes SDKs (AppCenter.bundle, AppCenterAnalytics.bundle, AppCenterCrashes.bundle) and contains MimeoKit.AppCenterIntegration class wired through the extension's Analytics protocol, sending session/usage telemetry and crash payloads to Microsoft App Center endpoints.
  3. 03Crash data captured by App Center Crashes is forwarded to a Sentry endpoint via MimeoKit.AppCenterIntegration.sendCrashEventsToSentry(crashData:fileName:); the crash payload (which can include user/email/project metadata attached as Sentry context) is sent to a third-party error-tracking service in addition to Microsoft.
OTHER EXTENSIONS

Is Mimeo Photos: Printed Memories safe?

Low risk

No summary available.

Mimeov6.4.2Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.mimeo.Mimeo.PhotoProject

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact