Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeSave to Cosmos
Findings · 3
+2 more findings locked
MEDIUM FINDINGS · 3
  1. 01Content script forwards arbitrary window.postMessage events to the privileged background message bus with no origin or schema validation, exposing GraphQL handlers (ADD_ELEMENT, IMPORT_ALL_BY_POST_URLS, CONNECT_ELEMENT_TO_CLUSTERS, EDIT_CLUSTERS_CONNECTIONS) to any visited page
  2. 02Sends user-tied analytics events to Mixpanel using a hardcoded project token; distinct_id is the user's Cosmos account id
  3. 03Crash and error reports sent to a hardcoded Sentry DSN with the extension release tag
+2 more findings locked
OTHER EXTENSIONS

Is Save to Cosmos safe?

Medium risk

No summary available.

Cosmos Entityv6.14.2Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.cosmos.staging.safariextension.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact