Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeSave to Raindrop.io
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Popup React app initializes Sentry SDK with hardcoded DSN; sends session-start events plus uncaught exception stack traces / breadcrumbs to sentry.io on every popup open
  2. 02On startup the background service worker downloads the user's full bookmark URL list from api.raindrop.io/v1/raindrops/links and keeps it in memory to drive the per-tab 'already saved' badge
  3. 03On user save action the extension dynamically injects assets/parse.js (and on highlight, assets/highlight.js) into the active tab via chrome.scripting.executeScript to read page metadata, selection, and image candidates, then POSTs them to api.raindrop.io
OTHER EXTENSIONS

Is Save to Raindrop.io safe?

Medium risk

No summary available.

Rustem Mussabekovv5.6.94Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026io.raindrop.safari.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact