Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeReadWriteMadeSimple Extension
Findings · 3
HIGH FINDINGS · 3
  1. 01Hardcoded Google Cloud Text-to-Speech API key shipped in extension bundle, used to send arbitrary user-selected text to Google with the developer's billable credential
  2. 02Content script harvests vendor session token from localStorage on every visited http/https page and writes it as a same-site cookie on every site, exposing the vendor api_key to arbitrary third parties
  3. 03Subscription status check sends user's vendor api_key to a staging endpoint (stagingada.skynettechnologies.us) from the production-shipped extension
OTHER EXTENSIONS

Is ReadWriteMadeSimple Extension safe?

High risk

No summary available.

RAJESH BHIMANIv1.0Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.skynettechnologies.Read-Write-Made-Simple.Read-Write-Made-Simple.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact