Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CookieManager - Cookie Editor

hdhngoamekjhmnpenphenpaiindoinpo
Risk Score
4.43
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 60,000
Rating 3.4
Last updated 2025-12-31 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer joue.quroi@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + *://*/*omain with no CSP: full cross-site cookie read/write by a Gmail-account dev with no scoped privacy policy.
  • Privacy policy is Google's generic account policy (scope_extension=false, admits data_collection+third_party_sharing) → +10.0 privacy score.
  • install_url_hijack flag set: onInstalled opens internal popup URL — minor but noted alongside uninstall_url_hijack flag.
  • Developer is a free-webmail Gmail user with no verified business identity or publisher badge.
  • Rating 3.4 is below 4.0, reflecting possible user dissatisfaction; combined with high-capability permissions raises concern.

Evidence

  • cookies + *://*/* manifest cookies HIGH permission paired with broad host access *:///*/* triggers ×1.2 amplifier; justified-broad discount does not apply (no DeveloperTools/PasswordManager CSP scoping).
  • privacy_policy_generic store Policy is Google account policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D: +10.0.
  • free_webmail_dev store Developer email joue.quroi@gmail.com; no verified publisher badge, no business domain. Reputation floor triggered at 7.5.
  • install_url_hijack crx install_url_hijack=true; target is internal popup path, not a 3rd-party site. Lower risk than external hijack but still flagged.
  • uninstall_url_hijack crx uninstall_url_hijack=true but target=null; no external redirect confirmed.
  • no_csp manifest content_security_policy=null on MV3; MV3 has strict default but absence of explicit CSP noted alongside broad host permissions.
  • rating_low store Rating 3.4; rating_count not provided. Combined with high-capability permissions warrants scrutiny.
  • code_clean crx 9 JS files scanned; code_findings_raw empty, obfuscation_score=0.0, no CVEs. Code quality pillar = 0.0.

Permissions Breakdown

  • cookies high Read/write all cookies across all sites — high-value exfil surface, especially paired with *://*/*.
  • storage low Local extension storage only; low standalone risk.
  • scripting medium Can inject scripts into pages; medium risk, core to cookie-editor function.
  • contextMenus low Adds right-click menu items; minimal risk surface.
  • *://*/* high Broad host access across all origins amplifies cookies and scripting permissions significantly.

Pillar Scores

Permissions7.50
Reputation7.50
Network2.00
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA 47c9c2da00cb…
Force block — not fired
Score recovered no
Elapsed 24.1s