Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeVenngo Browser Extension
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Background page sends URL, document title and meta-description / og: / twitter: tags of every visited http(s) page (outside venngo.com) to https://rest.venngo.com/perkCrawler/crawlPerks on each navigation completion while the user is logged in
  2. 02Background page programmatically injects in-page JavaScript via chrome.tabs.executeScript on every http(s) navigation; the same primitive is used to mount/unmount a Vue 'PerkNotification' overlay sourced from a bundled injectComponents.js
  3. 03Background page reads JWT session cookies from any visited *.venngo.com tab via chrome.cookies.get and uses them to silently authenticate the extension to rest.venngo.com
OTHER EXTENSIONS

Is Venngo Browser Extension safe?

Clean risk

No summary available.

Venngo Inc.v1.0Chrome Web Store
0Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026com.venngo.safariextension.browser

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact