Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeSave to Reader
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Sentry crash reporting initialized in BOTH background service worker AND <all_urls> content script with hardcoded DSN — undisclosed third-party data path; Sentry default request payload includes the host page URL when an error fires inside the injected UI
  2. 02Content script injected on <all_urls> and host_permissions <all_urls> — extension can read DOM and metadata of every visited page (save-page-to-Readwise primary function)
  3. 03Background service worker performs connectivity probes to api.ipify.org and ipv4/ipv6.icanhazip.com — these endpoints disclose the user's public IPv4/IPv6 to two third-party vendors on every online check
OTHER EXTENSIONS

Is Save to Reader safe?

Medium risk

No summary available.

Readwise, Incv0.17.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.readwise.Save-to-Reader.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact