Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeSpritz Extension
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Extension loads remote configuration from an unauthenticated public Firebase RTDB endpoint (extConfig.json) and forwards the JSON payload to the content script running on every page
  2. 02Background service worker hides its only network endpoint behind multi-layer string-table + Caesar-shifted base36 + reverse-arithmetic obfuscation that reconstructs https://spritzapp-916c3-default-rtdb.firebaseio.com/extConfig.json at runtime
  3. 03Content script registered for <all_urls> despite the extension only acting on user-clicked toolbar action; results in script + ~5MB Vue bundle being injected into every visited site even when not used
OTHER EXTENSIONS

Is Spritz Extension safe?

Medium risk

No summary available.

Spritz Holding LLCv0.2Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.spritzextension.ext

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact