Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeNordPass® (legacy)
Findings · 3
+8 more findings locked
MEDIUM FINDINGS · 3
  1. 01v7.6.21 manifest replaces host_permissions covering api-toggle.nordpass.com, api-toggle.stag.us.nordpass.com, and lastpass.com with http://*/* and https://*/* — granting the background service worker unrestricted outbound network access to any origin
  2. 02LastPass vault import feature accesses LastPass authentication endpoints and retrieves encrypted vault data
  3. 03Autofill ML metrics including visited page domains transmitted to NordPass API
+8 more findings locked
OTHER EXTENSIONS

Is NordPass® (legacy) safe?

Medium risk

No summary available.

NordPassv7.4.9Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+8 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026fooolghllnmhmmndgjiamiiodkpenpbb

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact