Am I Being Pwned? logoAm I Being Pwned?
Book a demo
Hometweak: mock and modify HTTP requests
Findings · 3
HIGH FINDINGS · 3
  1. 01intercept.bundle.js listens to window.postMessage without origin validation, allowing any page to add/delete/clear HTTP interception rules
  2. 02tsp.bundle.js captures full XHR/fetch request and response bodies on all pages and broadcasts them via window.postMessage('*') to any same-page script
  3. 03content-script.bundle.js broadcasts full extension storage (user token, session ID, plan data) via window.postMessage with wildcard target on page load
OTHER EXTENSIONS

Is tweak: mock and modify HTTP requests safe?

High risk

No summary available.

tweakv8.4.1Chrome Web Store
75Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026feahianecghpnipmhphmfgmpdodhcapi

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact