Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomePocketTube for Safari
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Hardcoded RapidAPI key + Imgur Client-ID embedded in the background service worker, used to anonymously upload arbitrary image data to imgur-apiv3.p.rapidapi.com on behalf of the developer's RapidAPI account.
  2. 02Background and popup JS POST behavioral telemetry (install, popup opens, group/playlist actions, share events) to api.mixpanel.com with a persistent per-install UID, three rotating Mixpanel project tokens, browser, version, and account-age fields. Mixpanel is not disclosed in the App Store listing.
  3. 03On a 60-minute alarm the background service worker POSTs the user's full PocketTube state - including the YouTube subscription list, custom groups/folders, channel metadata, watched-video counters, and Patreon/Paddle account email/tokens - to https://p.yousub.info/backup, the vendor's own server.
+1 more finding locked
OTHER EXTENSIONS

Is PocketTube for Safari safe?

Medium risk

No summary available.

Dmitry Nabokv18.4.48Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.pocketTubeExtension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact