Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomePower Thesaurus for Safari
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Authenticated browsing-history beacon: when the user is signed in to Power Thesaurus, the <all_urls> content script reports each visited site's origin (window.location.origin) to api.powerthesaurus.org via the SEND_EXTENSION_USAGE_ON_SITE GraphQL mutation, gated only on auth state — not on the user's analytics consent toggle
  2. 02Sentry error/perf telemetry hardcoded to a non-Sentry-cloud, vendor-personal-domain DSN at sentry.radyushin.com (radyushin.com is the maintainer's personal domain, distinct from the user-facing powerthesaurus.org), initialized in both the service worker and every <all_urls> content script
  3. 03Selection-based thesaurus lookup runs on <all_urls>: the selection.abeecb9f.js + selectionStart.ed1ec47e.js content-script pair is injected into every http(s) page and reads document.getSelection() / caretPositionFromPoint() on every selectionchange/mouseup; selected text is forwarded via runtime.sendMessage to the BG which queries api.powerthesaurus.org/graphql/web (findTermByUrl/term)
OTHER EXTENSIONS

Is Power Thesaurus for Safari safe?

Medium risk

No summary available.

Radyushin Pty Ltdv4.5.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026org.powerthesaurus.powerThesaurusExtension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact