Giant Coupons Official Extension
akdajpomgjgldidenledjjiemgkjcchc
Risk Score
6.04
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- webRequest + all-URLs host permissions give full traffic interception capability across every site visited.
- Extension stale 26 months with only 27 installs — high tail-attack-surface risk if silently updated.
- Privacy policy admits data collection and third-party sharing without retention disclosure.
- No developer name; developer email domain (status77.com) mismatches extension brand (giant.coupons).
- install_url_hijack opens third-party URL on install — install-time redirect to unknown target.
Evidence
- broad_host_permissions manifest host_permissions http://*/* and https://*/* combined with webRequest = full traffic interception on all sites.
- install_url_hijack manifest install_url_hijack=true; target not captured — opens unknown URL on install.
- stale_extension store Last updated June 28 2024; 26 months since update with only 27 installs — zombie tail risk.
- no_developer_name store developer_name is empty string; accountability gap.
- privacy_policy_third_party_sharing api Policy fetched, scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- small_install_high_perm api install_perm_anomaly: 27 installs with HIGH-tier permissions — tail attack surface confirmed.
- js_external_hosts crx Contacts api.giantcoupons.net and giant.coupons; developer email domain status77.com differs from both.
- no_csp manifest csp_present=false on MV3; no content_security_policy declared — minor amplifier.
Permissions Breakdown
- webRequest high Intercepts all HTTP/S requests across all URLs — broad surveillance capability.
- storage low Local extension storage; low inherent risk.
- http://*/* high Full read/write access to all HTTP pages.
- https://*/* high Full read/write access to all HTTPS pages including banking/auth.
- content_scripts *://*/* high Content scripts injected into every page; can exfiltrate DOM, credentials, PII.
Pillar Scores
Permissions8.00
Reputation6.50
Network4.50
Webstore5.50
Maintenance8.50
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:23
Listing SHA
de2b63e7d530…
Force block
— not fired
Score recovered
no
Elapsed
—