MILK — Cookie Manager
haipckejfdppjfblgondaakgckohcihp
Risk Score
4.68
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — no extension-specific data collection scope disclosed.
- cookies + broad host_permissions (<all_urls>) allows reading/writing cookies on every site visited.
- Uninstall URL hijack detected — extension registers a third-party URL on uninstall.
- innerHTML DOM-XSS sink in bundled JS; CSP present but cookie data processed in extension context is sensitive.
- months_since_update unknown — maintenance risk cannot be fully assessed.
Evidence
- broad_host_plus_cookies manifest cookies permission combined with http://*/* and https://*/* host_permissions = full cross-site cookie access.
- generic_privacy_policy store Privacy policy URL points to Google's account privacy page; scope_extension=false, admits data_collection+third_party_sharing.
- uninstall_url_hijack crx uninstall_url_hijack=true; target not captured but indicates 3rd-party redirect on removal.
- dom_xss_sink crx innerHTML assigned from variable in index.eb9364ec.js; CSP is self-only so external script blocked but internal XSS possible.
- maintenance_unknown store last_updated and months_since_update both null; cannot confirm active maintenance.
- featured_by_google store is_featured_by_google=true provides modest reputation signal but does not offset privacy policy gap.
- no_bad_hosts_no_cves crx cve_findings_raw empty, bad_host_hits empty, affiliate_hits empty — no threat-intel hits.
- js_external_hosts crx 8 external hosts in CSP/fingerprint (fb.me, fonts.google.com, github.com, material-ui.com, etc.) — documentation/CDN only.
Permissions Breakdown
- cookies high Can read/write all cookies across all origins given broad host_permissions.
- http://*/* high Broad host access to all HTTP sites amplifies cookies risk.
- https://*/* high Broad host access to all HTTPS sites amplifies cookies risk.
- tabs medium Can read tab URLs and metadata across all sites.
- contextMenus low Adds right-click menu entries; minimal standalone risk.
- storage low Local extension storage; no cross-origin exfil on its own.
Pillar Scores
Permissions5.50
Reputation4.00
Network2.00
Webstore3.50
Maintenance5.00
Privacy10.00
Code Quality0.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA
a044519e5cac…
Force block
— not fired
Score recovered
no
Elapsed
24.9s