Earlier quoted context omitted.
I did speak rather harshly in my prior comment, and for that I apologize. Worse, I did a very poor job of expressing the concern that motivated me to respond. But I think it's still fair to ask whether your initial comment has value. I understand that, as a user of 1Password's browser extension(s), you may well feel some concern that a similar vulnerability exists, and I don't think it's unreasonable to want reassura…
I understand a concern with my phrasing -- to be honest, I didn't put much thought into it as far as considering multiple interpretations. I have sent a message to 1Password through the official customer support channel to ask the same question posed here. I'll update once they reply.
> Thank you for taking the time to write to us here at AgileBits. The current version of the 1Password extension does not use regex to parse URLs for this exact reason. We don't autofill either, which also helps avoid issues like the one you mentioned.