Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomePieces Web Extension
Findings · 3
LOW FINDINGS · 3
  1. 01On user-triggered save, full DOM (XMLSerializer of document) of the active tab is sent to local Pieces OS app at http://localhost:1000 along with URL, page title, and any `.post-tag` text on the page
  2. 02Pieces SDK base path is hardcoded `http://localhost:1000` (cleartext HTTP). Page DOM, URL, and title are transmitted unencrypted on the loopback interface.
  3. 03externally_connectable is configured with `ids: ["*"]` and `matches: ["*://localhost/*"]`, allowing any web extension and any localhost-served page to send messages to the background script.
OTHER EXTENSIONS

Is Pieces Web Extension safe?

Low risk

No summary available.

Mesh Intelligent Technologies, Inc.v1.0Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026app.pieces.webExtension.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact