Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeVetted AI: Your Shopping Agent
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Order confirmation page scraping: extension reads product SKUs and order IDs from retail thank-you pages and sends to background via check_order/set_purchase messages
  2. 02Content script on all pages sends search query terms and store domain/pathname to api.vetted.ai via fetch_query mechanism on retail sites
  3. 03Affiliate cookie injection via silent background tab creation: extension opens an invisible tab to redirect URL, waits 7s to set affiliate cookie, then silently closes it
+1 more finding locked
OTHER EXTENSIONS

Is Vetted AI: Your Shopping Agent safe?

Medium risk

No summary available.

yahoo.commerce.browser.extensionv5.4.0Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026cjmfiochlaffhnellbhffgnjocahinnh

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact