Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeNordPass® Password Manager & Digital Vault
Findings · 2
LOW FINDINGS · 2
  1. 01host_permissions expanded from 3 specific NordPass/LastPass domains to http://* and https://* in v7.5.7, granting the background service worker the ability to make cross-origin requests to any URL without additional user consent.
  2. 02v7.5.7 adds chrome.scripting.executeScript logic that fires on extension update (onInstalled reason=update), iterating all open tabs and re-injecting every manifest-declared content script without a page reload.
OTHER EXTENSIONS

Is NordPass® Password Manager & Digital Vault safe?

Clean risk

No summary available.

NordPassv7.5.7Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026eiaeiblijfjekdanodkjadfinkhbfgcd

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact