Cookie-Editor
hlkenndednhfkekhgcdicdfddnkalmdm
Risk Score
4.74
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies permission grants full read/write access to all browser cookies across all sites.
- Developer uses free Gmail address with no verified business identity; no developer name listed.
- 28 months since last update — stale for a 2M-install extension.
- Privacy policy fetched but scope_extension=false and does not confirm data_collection=false explicitly for this extension; third_party_silence=true adds uncertainty.
- 11 external JS hosts referenced (affiliate/sponsor links visible); no CSP on MV3 — network surface broader than expected.
Evidence
- cookies_permission manifest cookies permission declared with no host_permissions — applies to all domains accessible to the browser.
- free_webmail_dev store Developer email christopheextensions@gmail.com; developer_name empty; no verified publisher badge.
- stale_extension store Last updated February 2024, 28 months ago; 2M installs creates large attack surface if compromised.
- privacy_policy_scope api Policy fetched (879 chars) but scope_extension=false; data_collection=false, retention=false, third_party_silence=true.
- external_hosts crx 11 external hosts including aurainc.sjv.io, skillshare.eqcm.net, namecheap.pxf.io — affiliate/sponsor link domains.
- geo_diversity api JS hosts span 4 countries (CA, IE, IN, US); triggers +1.5 network penalty for DeveloperTools category.
- no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty — clean code scan.
- verified_publisher store verified_publisher=true but months_since_update=28 >18mo triggers invariant 0c; discount capped at -1.0.
Permissions Breakdown
- cookies high Full read/write access to all browser cookies; core to stated function but high abuse potential.
- tabs medium Access to tab URLs and metadata; needed to scope cookie editing to active tab.
- storage low Local extension storage for preferences; low inherent risk.
- sidePanel low Displays extension UI in side panel; no data access.
Pillar Scores
Permissions4.50
Reputation6.50
Network3.50
Webstore3.00
Maintenance6.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| v3.6" U9F4=4SiS([!+!]) dK8=" | 4.79 | Medium | review | 2026-08-05 |
| dfb[[${98991*97996}]]xca | 4.86 | Medium | review | 2026-08-05 |
| v3.6&n903072=v943206 | 4.88 | Medium | review | 2026-08-05 |
| v3.6</script><script>dkHI(9914)</script> | 5.02 | Medium | review | 2026-07-29 |
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%64%6B%48%49%28%39%34%33%31%34%29%22 | 5.05 | Medium | review | 2026-07-29 |
| v3.6" xiPU=dkHI([!+!]) thG=" | 4.73 | Medium | review | 2026-07-29 |
| dfb__${98991*97996}__::.x | 4.57 | Medium | review | 2026-07-29 |
| dfb{{98991*97996}}xca | 5.12 | Medium | review | 2026-07-29 |
| bfgx5182%C0%BEz1%C0%BCz2a%90bcxhjl5182 | 4.41 | Medium | review | 2026-07-29 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 4.87 | Medium | review | 2026-07-29 |
| <%={{={@{#{${dfb}}%> | 4.72 | Medium | review | 2026-07-29 |
| v3.69182912 | 4.81 | Medium | review | 2026-07-29 |
| v3.6 | 4.74 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
a099bfe70e3b…
Force block
— not fired
Score recovered
no
Elapsed
21.5s