Am I Being Pwned? logoAm I Being Pwned?
Contact usScan my org
HomeTextRecruit Extension
Findings · 3
+1 more finding locked
HIGH FINDINGS · 3
  1. 01iframe.js accepts window messages from any origin without verification and forwards them to chrome.runtime and to the embedded iframe
  2. 02Content script scrapes candidate PII (names, phone numbers, source IDs) from ATS pages and sends it to the remote app.textrecruit.com iframe via postMessage
  3. 03Extension embeds remote application from app.textrecruit.com in an iframe injected into every web page, giving the remote server control over extension UI behavior
+1 more finding locked
OTHER EXTENSIONS

Is TextRecruit Extension safe?

High risk

No summary available.

ICIMS, Inc.v4.0.6Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026hohjiogaaddpcpakfaegfacbaggphald

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact