Am I Being Pwned? logoAm I Being Pwned?by Bay Area Labs
Contact usScan my org
HomeWeb Data Assistant
Findings · 3
MEDIUM FINDINGS · 3
  1. 01Extension extracts CSP nonce values from HTTP response headers on all URLs and passes them into injected page scripts to bypass Content Security Policy
  2. 02Extension injects global window.sendMessage function into every visited page, exposing chrome.runtime.connect() to page scripts
  3. 03User-defined JavaScript rule strings stored in chrome.storage.sync are evaluated as live script elements in document.head on every visited page without sandboxing
OTHER EXTENSIONS

Is Web Data Assistant safe?

Medium risk

No summary available.

Web Data Assistantv2.2.1Chrome Web Store
45Risk

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

Updated 30 May 2026oacpegaegonlmnobkoeiiegdccgcmpnj

Am I Being Pwned?

Protecting organizations from malicious browser extensions.

© 2026 Bay Area Labs Inc. All rights reserved.

BlogFree Org ScanHow it worksSecurityFor VendorsFAQThreat Intel FeedAPI DocsPrivacy PolicyTerms of ServiceContact