Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeOneLogin for Safari
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Content scripts run on every http(s) page and scan the DOM for login forms (<input type=password>, login/email keywords) using a 5MB+ embedded library of per-site form selectors and step automation, in line with the extension's documented password-manager function.
  2. 02Hardcoded Airbrake error-reporting credentials (projectId 130482, projectKey 09448f758a572e3a7b12d6d85bdfc8cf) embedded in background.js post error notices including extension URL/state to api.airbrake.io for 10% of errors. Not disclosed in App Store listing.
  3. 03Dynamic declarativeNetRequest rules append the extension version (plugin_version=4.0.2) to any main_frame request whose path matches /client/apps/select/*, /start/*, or /launch/* with no host restriction, leaking the OneLogin extension version to non-OneLogin hosts that happen to use those URL paths.
OTHER EXTENSIONS

Is OneLogin for Safari safe?

Low risk

No summary available.

OneLogin, LLCv4.0.2Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.onelogin.OneLoginSafariAppExtension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact