Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeSmartPlay for Safari
Findings · 3
+2 more findings locked
LOW FINDINGS · 3
  1. 01Content script (matches: <all_urls>) responds to unauthenticated 'get-op-vlaues' window.postMessage by leaking extension UUID origin URL plus stored userSetting object back to the page via postMessage with target '*'.
  2. 02Content script attaches a DOMSubtreeModified listener on document.body for every page on the web, firing on every DOM mutation to test location.host and inject UI on Netflix.
  3. 03Hardcoded shared OMDb API key '97ca1897' embedded in page-injected script; queried with movie title harvested from Netflix DOM and rendered into the page via innerHTML interpolation of the third-party JSON response.
+2 more findings locked
OTHER EXTENSIONS

Is SmartPlay for Safari safe?

Low risk

No summary available.

Best App Limitedv3.5Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+2 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.9bestapp.smartplay.ext

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact