Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeStreaming+ for Netflix
Findings · 3
+4 more findings locked
HIGH FINDINGS · 3
  1. 01Hardcoded Google Cloud API key (YouTube Data API v3) shipped in content script — usable by anyone reading the bundle to spend the vendor's Google Cloud quota.
  2. 02Movie / show metadata sent to OMDB API over cleartext HTTP, exposing what the user is browsing on Netflix to anyone on the network path.
  3. 03On the first 'activation' message of each session the background script silently injects a hidden iframe to https://unogs.com/ — a third-party Netflix-tracking service — without disclosure.
+4 more findings locked
OTHER EXTENSIONS

Is Streaming+ for Netflix safe?

High risk

No summary available.

枭波 王v2.3.0Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+4 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026com.eplussoft.webext.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact