Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomePapers by ReadCube Extension
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Page-dispatched CustomEvents (`rcExtDownloadInit` / `rcExtDownloadUrlInit`) cause the extension to fetch an attacker-supplied URL with the user's credentials and (when isUpload) upload the response body to the user's ReadCube library.
  2. 02webRequest.onHeadersReceived listener registered on `<all_urls>` (responseHeaders) observes the response headers of every main_frame/sub_frame request the user makes, plus a second listener on `<all_urls>` that inspects redirect Location headers on every navigation.
  3. 03Background service worker reports errors to Sentry SaaS (sentry.io) including extension internal context; project `4509111282499584` on `o252134.ingest.us.sentry.io`.
+1 more finding locked
OTHER EXTENSIONS

Is Papers by ReadCube Extension safe?

Medium risk

No summary available.

Digital Science & Research Solutions Inc.v6.7.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.readcube.ReadCube-Papers-Extension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact