Session Export Tool
mimplmibgdodhkjnclacjofjbgmhogce
Risk Score
5.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies + <all_urls>: can silently read session cookies from any website and export them.
- clipboardWrite enables cookie/session data exfiltration to clipboard without user confirmation.
- Privacy policy is Google's generic policy — does not disclose what THIS extension collects.
- Free-webmail developer (gmail) with no verifiable business identity; unverifiable accountability.
- Small install count (41) with high-tier permissions is a tail-attack-surface anomaly.
Evidence
- cookies + <all_urls> manifest Extension declares cookies permission with <all_urls> host access — can exfiltrate any site session.
- generic privacy policy store Policy URL points to Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
- free-webmail developer store Developer email vitaliyacloud@gmail.com; no verified business domain or publisher badge.
- small_install_high_perm api 41 installs with HIGH-tier permissions (cookies+<all_urls>) — install_perm_anomaly flagged.
- external IP-lookup hosts crx JS contacts api.ipify.org and ifconfig.me to retrieve user IP address — fingerprinting capability.
- no CSP (MV3) manifest csp_present=false; MV3 provides strict default but no explicit extension page CSP declared.
- apple.com host permission manifest Specific broad host permission for *.apple.com with no stated Apple-specific functionality.
- no verified publisher store verified_publisher=false, is_featured_by_google=false; no accountability signals present.
Permissions Breakdown
- cookies high Can read all cookies across all URLs via <all_urls> host permission — high exfil potential.
- activeTab low Scoped to user-activated tab only; limited standalone risk.
- clipboardWrite medium Writes to clipboard; combined with cookies+<all_urls> enables silent session exfil.
- https://*.apple.com/* medium Specific high-value target host; narrow but notable.
- <all_urls> high Broad host access amplifies cookies permission — can harvest sessions from any site.
Pillar Scores
Permissions7.00
Reputation7.50
Network4.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 16:32
Listing SHA
80e1aed76f9f…
Force block
— not fired
Score recovered
no
Elapsed
—