Disable Cookies
lkmjmficaoifggpfapbffkggecbleang
Risk Score
4.51
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched and admits data collection + third-party sharing but is NOT scoped to this extension — worst-case privacy posture.
- Free-webmail developer (gmail.com) with no 'Offered by' name; accountability gap.
- browsingData + contentSettings combo allows silent clearing of all cookies/browsing data across all sites.
- Uninstall URL hijack sends user to developer domain on removal — minor monetization/tracking signal.
- Featured badge and verified publisher discount capped to -1.0 due to months_since_update=17 exceeding 18mo threshold imminently; policy still unscoped.
Evidence
- privacy_policy_scope_mismatch api Policy fetched (55k chars), scope_extension=false, data_collection=true, third_party_sharing=true → D rule fires: +10.0 privacy.
- free_webmail_dev_no_name store developer_email=singleclickapps@gmail.com, developer_name empty; reputation +1.5 free-webmail, +1.0 no Offered-by name.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; reputation discounts applied but capped by months=17 approaching 18mo threshold.
- uninstall_url_hijack crx onUninstall → singleclickapps.com/disable-cookies/removed-chrome.html; webstore +3.0 but category-context reduces concern.
- install_url_opens_settings crx install_url_hijack=true targeting chrome://settings/content/siteData — benign internal page, not 3rd-party.
- no_csp manifest content_security_policy=null on MV3; MV3 strict default applies, no +2.0 MV2 penalty triggered.
- high_perm_browsingData_contentSettings manifest Two HIGH permissions; justified-broad discount (-1.5) applied as PrivacyTool category matches stated function.
- no_code_findings_no_cves crx code_findings_raw=[], cve_findings_raw=[], obfuscation_score=0.0; code quality and CVE pillars score 0.
Permissions Breakdown
- contentSettings high Can control browser content settings (cookies, JS, plugins) per-site — core function but high capability.
- browsingData high Can delete cookies, cache, history, and other browsing data across all sites.
- tabs medium Access to tab URLs and navigation events; needed to identify current site.
- contextMenus low Adds right-click menu entries; low risk on its own.
- storage low Local extension settings persistence; low risk.
Pillar Scores
Permissions5.50
Reputation4.50
Network0.00
Webstore4.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA
c2f1d28cc781…
Force block
— not fired
Score recovered
no
Elapsed
25.9s