Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomePayPal Honey for Safari
Findings · 3
+4 more findings locked
MEDIUM FINDINGS · 3
  1. 01Extension declares SFSafariWebsiteAccess Level: All and ships a page-detector content script (h1-check.js) that runs on every top-level page the user navigates to, evaluating server-supplied page-detector recipes against page DOM/URL to decide whether the site is a known store.
  2. 02Honey-Checkout pipeline pulls remote 'recipe' / 'VIM' bundles from v.joinhoney.com and cdn-checkout.joinhoney.com that drive DOM-level scraping and automated actions (CSS selector reads, regex extraction, click simulation, suppression of native dialogs) on supported store pages.
  3. 03Periodic cross-domain identity heartbeat: once every 24h the extension fetches https://history.paypal.com/targeting/set-plugin?src=honey, marking the user as a Honey user inside PayPal's targeting (advertising / tracking) subdomain.
+4 more findings locked
OTHER EXTENSIONS

Is PayPal Honey for Safari safe?

Medium risk

No summary available.

Honeyv19.1.2Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+4 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.joinhoney.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact