Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeSplit Desktop Extension
Findings · 3
+3 more findings locked
HIGH FINDINGS · 3
  1. 01Every main-frame navigation across all websites is reported to api2.split.co by extracting the registrable domain and querying /v1/check_domain on chrome.webNavigation.onCommitted.
  2. 02Affiliate-link hijack: when a user clicks a 'Shop' offer or autoshop fires, the extension calls /v1/action_ext or /v1/shop_it_auto and replaces the active tab URL with a server-supplied affiliate redirect (`t.submission.url` / `t.url`).
  3. 03Content script scrapes Google search and Google Images result domains and ships them to api2.split.co/v1/merchants/check_domains via the background page.
+3 more findings locked
OTHER EXTENSIONS

Is Split Desktop Extension safe?

High risk

No summary available.

Split Technologies, Inc.v2.14Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026co.split.macapp.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact