Awesome Cookie Manager
hcpidejphgpcgfnpiehkcckkkemgneif
Risk Score
4.53
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Privacy policy is Google's own policy (not scoped to this extension) — admits data collection and 3rd-party sharing without extension scope: Privacy pillar maxed.
- 7 medium-severity CVEs in bundled jquery-ui@1.8.23 (unfixed, version predates all fix points) with eval_user_input in the same library.
- Brand impersonation: description claims 'Google Chrome cookies' and brand_mention confirms unverified Google brand reference.
- code_findings confirm eval_user_input + function_constructor + dynamic script creation in bundled libraries alongside <all_urls> + cookies access.
- No developer name supplied; verified_publisher flag present but privacy policy is a Google generic URL, undermining trust signal.
Evidence
- privacy_policy_generic_google store Privacy policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
- 7x_medium_CVEs_jquery_ui_1.8.23 crx jquery-ui@1.8.23 carries 7 moderate CVEs; all unfixed at bundled version. >=3 medium CVEs → +2.0; +4×0.5 additional unique CVEs → +2.0 cap.
- eval_user_input_in_jquery_ui crx eval_user_input found in jquery-ui.min.js alongside 7 CVEs and <all_urls>+cookies — high exploitation surface.
- brand_impersonation_google store brand_mention.is_impersonation=true, brands_mentioned=['google'], confirmed_owner=false, not verified by Google.
- cookies_plus_all_urls manifest cookies HIGH permission paired with <all_urls> host_permission → ×1.2 multiplier applied; category discount applied for DeveloperTools.
- no_developer_name store developer_name is empty string; no 'Offered by' name raises identity accountability concern.
- function_constructor_and_dynamic_script crx function_constructor (+2.5) and script_src_dynamic (+3.0) found in jquery.min.js; code quality elevated.
- verified_publisher_cap_applied store verified_publisher=true but cve_findings_raw non-empty → v3.5 invariant 0c caps discount to -1.0 on reputation.
CVE Exposures (7)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-41182 | jquery-ui@1.8.23 | moderate | 1.13.0 | XSS in the `altField` option of the Datepicker widget in jquery-ui |
| CVE-2021-41184 | jquery-ui@1.8.23 | moderate | 1.13.0 | XSS in the `of` option of the `.position()` util in jquery-ui |
| CVE-2022-31160 | jquery-ui@1.8.23 | moderate | 1.13.2 | jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in |
| CVE-2016-7103 | jquery-ui@1.8.23 | moderate | 1.12.0 | jQuery-UI vulnerable to Cross-site Scripting in dialog closeText |
| CVE-2021-41183 | jquery-ui@1.8.23 | moderate | 1.13.0 | XSS in `*Text` options of the Datepicker widget in jquery-ui |
| CVE-2012-6662 | jquery-ui@1.8.23 | moderate | 1.10.0 | jquery-ui Tooltip widget vulnerable to XSS |
| CVE-2010-5312 | jquery-ui@1.8.23 | moderate | 1.10.0 | Cross-site Scripting in jquery-ui |
Permissions Breakdown
- cookies high Full read/write access to all cookies on any site; core to extension function but high sensitivity.
- <all_urls> (host_permissions) high Broad host access enabling cookie reads across every visited site.
- tabs medium Can read tab URLs and metadata; moderate privacy risk.
- activeTab low Limited to user-invoked current tab; lower blast radius.
- storage low Local extension storage only; no cross-origin risk.
Pillar Scores
Permissions5.70
Reputation6.00
Network0.00
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality7.50
CVE Exposure5.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA
7b2aee80c25d…
Force block
— not fired
Score recovered
no
Elapsed
39.7s