Am I Being Pwned? logoAm I Being Pwned?
Book a demo
HomeVocably for Safari
Findings · 3
+1 more finding locked
MEDIUM FINDINGS · 3
  1. 01Service worker forwards every translation-request payload (selected text + surrounding-sentence context + initiator + language pair) to PostHog product analytics (us.i.posthog.com) via Fo.capture('analyze_requested', analyzePayload), associating the captured user-generated content with the user's email address and Cognito sub via Fo.identify(...).
  2. 02Translation request payload (selected text + surrounding sentence + language pair) is POSTed to the vendor's own backend api.vocably.pro/analyze with the user's Cognito JWT in the Authorization header — this is the extension's primary disclosed function (translate selected text, build flashcards).
  3. 03Content script is injected into every frame of every URL ('matches':['*://*/*'], 'all_frames':true) and registers global mouseup/mousedown/dblclick/keyup listeners on document plus a selection-change watcher to render the translation popup over user-selected text. This broad scope is required for the extension's primary function (translate-on-selection on any website).
+1 more finding locked
OTHER EXTENSIONS

Is Vocably for Safari safe?

Medium risk

No summary available.

Vocably B.V.v1.760.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

+1 more finding not shown

Book a call to see all findingsScan your browser
Updated 30 May 2026pro.vocably.Vocably.Extension

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogHow it worksSecurityFor VendorsFAQAPI DocsPrivacy PolicyTerms of ServiceContact