Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeSavee for Safari
Findings · 3
LOW FINDINGS · 3
  1. 01Background service worker exposes an unrestricted authenticated fetch proxy (onFetch) that performs fetch(url, {credentials:'include'}) on any URL supplied by the content script with no allowlist or origin/path validation.
  2. 02When the user invokes Save (icon click, 'Add to Savee' context menu, or in-page save button), the extension transmits the current page URL, document title, and a Safari tabs.captureVisibleTab JPEG screenshot to savee.com via the UploadItemFromRemoteMutation GraphQL call.
  3. 03PostHog product analytics is wired into the bundled web client with a hardcoded production project key (phc_lWQOR1220R7hUhgyZeNqbOZ8FpVLYuNIYyA8r4DHcJ7) pointing at a self-hosted instance at https://t.savee.com.
OTHER EXTENSIONS

Is Savee for Safari safe?

Low risk

No summary available.

Savee LLCv3.0.16Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026it.savee.safari.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact