Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeTMetric for Safari
Findings · 2
LOW FINDINGS · 2
  1. 01Content scripts on 60+ third-party productivity tools scrape issue/project/task metadata from the DOM and POST it to TMetric API servers when the user opts in via the integrations settings page.
  2. 02manifest.json declares broad optional_permissions of `http://*/*` and `https://*/*`, allowing the user to grant the extension origin access to arbitrary domains so dynamic content-script registration can target self-hosted productivity tools (e.g. on-prem Jira/GitLab/Bitbucket Server/Bugzilla).
OTHER EXTENSIONS

Is TMetric for Safari safe?

Clean risk

No summary available.

Devartv5.0.27Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.tmetric.app.safari.extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact