Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeSafeBase by Drata
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01Captures request headers from authenticated questionnaire portals (Microsoft Forms, ZenGRC, ServiceNow, ZipHQ, FormStack, Prevalent, UpGuard) via chrome.webRequest.onSendHeaders and stores them in chrome.storage.session keyed by tab id.
  2. 02Uploads sanitized page HTML (head + body) of supported questionnaire portal pages to Google Cloud Storage via a signed PUT URL minted by SafeBase's chrome-extension API when the user fills out a portal.
  3. 03Sends product analytics events to Segment.io (api.segment.io/v1/batch) keyed by SafeBase-issued ajs_user_id and ajs_anonymous_id cookies read via chrome.cookies.get from app.safebase.io.
+2 more findings locked
OTHER EXTENSIONS

Is SafeBase by Drata safe?

Low risk

No summary available.

chrome-developer-publisherv2.5.2Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026mfmcakkhgmcedieeoahcnomefgigcnhm

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact