Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeVideo Downloader for U
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Facebook CSRF token (fb_dtsg_ag) intercepted from outgoing request headers and stored; used to make authenticated API calls on behalf of the user
  2. 02Twitter/X CSRF cookie (ct0) extracted from user's browser and forwarded to background script which makes authenticated Twitter API requests using a hardcoded Bearer token
  3. 03X-Frame-Options response header stripped from all facebook.com responses, allowing Facebook pages to be embedded in arbitrary iframes
OTHER EXTENSIONS

Is Video Downloader for U safe?

Medium risk

No summary available.

VideoUnitv1.1.4Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026dkbccihpiccbcheieabdbjikohfdfaje

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact