Am I Being Pwned? logoAm I Being Pwned?
Contact usScan my org
HomeTalk & Comment - Voice notes anywhere
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Transmits the active tab URL to talkandcomment.com when a recording is started, as part of recording permission and educational/business context detection.
  2. 02Transmits analytics events to PostHog (us.i.posthog.com) and Google Analytics (GA4) with a persistent user identifier and extension usage data.
  3. 03Sentry error reporting activated with live DSN in v4.3.3. Previously the VITE_SENTRY_DSN was an empty string (disabled). The new config bundle hardcodes a production DSN pointing to ingest.us.sentry.io. Sentry is initialized in both the service worker context and the content script context (which runs on all_urls). The setUserContext helper reads user_id, user_hash, and anonymous_user_id from chrome.storage.local and attaches them to Sentry events. The beforeBreadcrumb filter only strips chrome-extension:// URLs, allowing regular page URLs to flow through as breadcrumbs on any site where an error occurs.
OTHER EXTENSIONS

Is Talk & Comment - Voice notes anywhere safe?

Low risk

No summary available.

TalkandComment.comv4.0.1Chrome Web Store
20Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026djnhkfljnimcpelfndpcjcgngmefaobl

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact