Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomePerkSpot: Save While You Shop
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Content script on all http(s) sites checks document.referrer/URL for affiliate-network markers and reports the user's signed-in PerkSpot userId + visited hostname to a Snowplow analytics collector when a match occurs.
  2. 02Background service worker registers webNavigation.onCompleted listener that, on every navigation, looks up the destination URL against a server-supplied merchant mapping table and (when offer is active) injects offer modals — sending PerkSpot userId + merchant context to PerkSpot's API server.
  3. 03WebExtension manifest declares 'cookies' and 'identity' permissions even though no extension code uses chrome.cookies.* or chrome.identity.* APIs — over-broad permission scope.
OTHER EXTENSIONS

Is PerkSpot: Save While You Shop safe?

Low risk

No summary available.

PerkSpotv36.4.3Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.perkspot.safari.desktop.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact