Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomePaper
Findings · 3
+3 more findings locked
MEDIUM FINDINGS · 3
  1. 01Security response headers (X-Frame-Options and Content-Security-Policy) are removed from app.paper.co sub-frame responses via declarativeNetRequest dynamic rules
  2. 02Full Google Docs document content (title and body text) fetched via Google OAuth token on user action and returned to the content script
  3. 03Extension reads Google Docs document content via OAuth2-authenticated Docs API and transmits it to the Paper tutoring interface
+3 more findings locked
OTHER EXTENSIONS

Is Paper safe?

Medium risk

No summary available.

Paperv3.8.8Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026flkenbnefhfhjeflinndcnlepkapgigl

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact