Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeOkta Extension App
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01Background sends product-analytics events to third-party Pendo SaaS (app.pendo.io/data/track) tagged with the user's Okta userId (visitorId), orgId (accountId), and event properties, using a hardcoded x-pendo-integration-key.
  2. 02On every webNavigation completion the BG injects preload-content.js into every frame of every http(s) URL via chrome.tabs.executeScript; the preload reads the page's forms/inputs and queries chrome.storage to decide whether to escalate to full content-script injection.
  3. 03Background subscribes chrome.webRequest.{onSendHeaders,onCompleted,onBeforeRedirect,onErrorOccurred} for `{urls:['<all_urls>'], types:['main_frame']}` to record per-tab navigation timing/method/status sequences for Okta auth-failure detection telemetry.
+2 more findings locked
OTHER EXTENSIONS

Is Okta Extension App safe?

Medium risk

No summary available.

Okta, Inc.v6.45.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026okta.ExtensionLauncher.Extension.WebExtension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact