Disable Content-Security-Policy
ieelmcmcagommplceebfedjlakkhpden
Risk Score
4.53
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Core function strips CSP from all sites visited, eliminating XSS defenses for users who forget to disable it.
- Privacy policy is Google's generic account policy — completely unscoped to this extension (scope_extension=false, data_collection=true, third_party_sharing=true).
- browsingData permission allows wiping cookies/cache/history with no apparent functional need beyond CSP disabling.
- 21 months since last update; extension is approaching stale territory with no changelog evidence.
- External host contact to web.whatsapp.com is unexplained for a CSP-disabling developer tool.
Evidence
- core_function_security_risk manifest Extension's stated purpose is to disable CSP via declarativeNetRequest header removal — exposes users to XSS on every visited site.
- privacy_policy_generic store Policy URL is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true per classification.
- browsingData_unexplained manifest browsingData permission declared; no functional justification for a CSP-stripping dev tool.
- external_host_unexplained crx js_external_hosts includes web.whatsapp.com — no clear reason for a CSP-disable tool to reference WhatsApp.
- maintenance_stale store Last updated September 2024; 21 months since update (6-12mo band exceeded, 12-24mo = +6.0).
- no_csp_mv3 crx content_security_policy is null; MV3 provides strict default so no v2 network penalty applies.
- rating_below_threshold store Rating 3.5; no confirmed count so +1.0 rating<3.0 rule not triggered, but low satisfaction signal.
- cve_findings_empty crx No CVEs found in bundled libraries; cve_findings_raw is empty.
Permissions Breakdown
- storage low Stores extension settings locally; minimal risk.
- activeTab medium Access to currently active tab on user interaction; scoped but grants page content access.
- browsingData high Can clear cookies, cache, history — significant user data destruction capability.
- declarativeNetRequest medium Can modify/block network requests including CSP headers; core stated function but powerful.
Pillar Scores
Permissions5.50
Reputation5.00
Network0.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| v3.6 | 4.53 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.41 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA
d5b358ccde0f…
Force block
— not fired
Score recovered
no
Elapsed
21.2s