Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeVMP™ Pass Password Manager
Findings · 3
+3 more findings locked
CRITICAL FINDINGS · 3
  1. 01Master password transmitted in plaintext JSON to developer-controlled server at passwordmanager.themebeaver.com:5443
  2. 02AES-256-GCM vault encryption key stored unprotected in chrome.storage.local as 'encryption_key_base64' — accessible to any extension with storage permission or via local compromise
  3. 03Custom analytics backend at passwordmanager.themebeaver.com:5443 receives user email address, full page URL, page title, and user credentials domain on every autofill and autosave event
+3 more findings locked
OTHER EXTENSIONS

Is VMP™ Pass Password Manager safe?

Critical risk

No summary available.

VPN Master Prov2.5.0Chrome Web Store
100Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+3 more findings not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026bpgiafopgkpbdmjbklogjficokcaiimd

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact