Am I Being Pwned? logoAm I Being Pwned?
Book a demo
Homescite extension
Findings · 2
LOW FINDINGS · 2
  1. 01Content script runs on <all_urls> and reads document.documentElement.innerHTML, document.title and window.location.href on every page; DOIs found via per-site selectors / regex are sent to https://api.scite.ai/papers/{doi} and /tallies/{doi} (GET).
  2. 02externally_connectable.matches includes '*://localhost/*' alongside scite.ai, allowing any locally-running webserver page to send messages to the extension via chrome.runtime.sendMessage.
OTHER EXTENSIONS

Is scite extension safe?

Low risk

No summary available.

scitev1.34.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026ai.scite.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact