Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeProton Pass for Safari
Findings · 3
+1 more finding locked
LOW FINDINGS · 3
  1. 01Content script orchestrator.js runs on https://*/* and http://*/* (all sites) to detect login/credit-card/identity forms, capture submitted credentials, and perform autosave/autofill via native messaging to the host app
  2. 02webauthn.js content script runs in MAIN world at document_start on https://*/* and http://*/* (excluding Proton's own domains) and overrides navigator.credentials.create / navigator.credentials.get / PublicKeyCredential.isConditionalMediationAvailable / PublicKeyCredential.isUserVerifyingPlatformAuthenticatorAvailable to intercept WebAuthn / passkey ceremonies before the browser's built-in authenticator sees them
  3. 03Background service worker fetches form-detection rules and the public-suffix list from proton.me on demand to drive content-script field classification on arbitrary websites
+1 more finding locked
OTHER EXTENSIONS

Is Proton Pass for Safari safe?

Clean risk

No summary available.

Proton AGv1.36.0Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026me.proton.pass.catalyst.safari-extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact