Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeNordPass Password Manager
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01Background JS uploads per-form telemetry (full pageUrl, formSelector, predicted form type, prediction scores, field types, model & extension versions, browser name/version) to api.nordpass.com/v1/autofill/collect/metrics in batches of >1000.
  2. 02Background JS fetches a remote-updatable TensorFlow.js model bundle from downloads.npass.app/extension/models_82.json on startup and every ~12 hours; the downloaded JSON is loaded into the on-device form/submit/field classifiers and immediately drives autofill behavior on every site.
  3. 03Content scripts (classifier.js, content.js) inject on every http(s) page to detect and autofill login/credit-card/identity forms via on-device TF.js classifiers.
+2 more findings locked
OTHER EXTENSIONS

Is NordPass Password Manager safe?

Medium risk

No summary available.

Nordvpn S.A.v7.2.16Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.nordpass.safari.app.password.manager.safariExtension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact