Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeSocial Post Mate (Commenter AI partner)
Findings · 3
+9 more findings locked
HIGH FINDINGS · 3
  1. 01Server-controlled API endpoint URL stored in chrome.storage.sync directs all post content and comment data to a remotely-configurable destination without domain validation
  2. 02commenter.ai page can set arbitrary API endpoint URL via localStorage, which the extension reads and stores as the destination for all data transmissions
  3. 03commenter.ai authentication token extracted from cookies and stored in chrome.storage.local, then sent as Bearer token and passed through message channels
+9 more findings locked
OTHER EXTENSIONS

Is Social Post Mate (Commenter AI partner) safe?

High risk

No summary available.

socialpostmatev5.0.1Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+9 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026ffebfjkgjgbpmnoogjjdgfkmiobngdnf

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact