Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeQuillBot: AI Writing Assistant
Findings · 3
+4 more findings locked
MEDIUM FINDINGS · 3
  1. 01On Safari, detect-editors.js fetches its own JS source via runtime.getURL and calls iframe.contentWindow.eval() on every same-origin/about:blank/srcdoc/blob: iframe found on every page, propagating the QuillBot content script into nested frames it could not directly inject into.
  2. 02Service worker dispatches Snowplow page-view tracking (event=pv) including the current pageUrl, pageTitle and referrer to the vendor's collector; sampling rate defaults to 100 (every event) and tracking is enabled by default unless the user toggles enableTracking.
  3. 03Detect-editors content script and an empty <all_urls> CSS injection run on every page (all frames) to autodetect editable text fields, and dynamically import quillbot-content.js when an editor is focused.
+4 more findings locked
OTHER EXTENSIONS

Is QuillBot: AI Writing Assistant safe?

Medium risk

No summary available.

QuillBot, a Learneo Inc. businessv4.71.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+4 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.quillbot.safari.macos.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact