Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeTotal Password for Safari
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Content script registered on http://*/* and https://*/* (all_frames:true, document_start) parses every form on every page the user visits and, on submit, sends form contents (username, password, identity fields) to the background page via the forge bridge for password-manager save/update prompts.
  2. 02Sentry telemetry is enabled-by-default (default remote config `sentryEnabled:"enabled"`) and reports stack traces, breadcrumbs, and user identifiers (per-install UUID, build hash) to a Sentry DSN fetched at runtime from cdn.wl.totalpassword.com/settings/config.json.
  3. 03Hardcoded Google Maps Static API key 'AIzaSyBkMFzpyiUPV5hO6y7kpccwOmIjSdP0Zd4' shipped in extension bundle, fetched whenever the user opens the SecureMe session-detail dialog, allowing third-party reuse / quota abuse if extracted.
+1 more finding locked
OTHER EXTENSIONS

Is Total Password for Safari safe?

Medium risk

No summary available.

Total Security Limitedv1.0.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026net.protected.safari.TotalPassword.webextension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact