EZTOOL.VN
oeifegedbdbjcmooefolmnchojjihaap
Risk Score
6.73
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- cookies+webRequest+management on Facebook/TikTok/Microsoft enables session theft and account takeover.
- Access to 7 disposable/temp-mail services is anomalous for a 'Facebook account management' tool — suggests credential farming.
- Brand impersonation: uses Facebook brand in title/description while developer domain is gmail.com, not Facebook.
- Privacy policy not scoped to this extension, no data collection disclosed, third-party silence flag raised.
Evidence
- cookies+webRequest on social platforms manifest cookies and webRequest cover Facebook, Instagram, TikTok, Microsoft — enables session/token interception.
- management permission manifest Can enumerate and disable other Chrome extensions; significant privilege for a social-management tool.
- temp-mail host access manifest 7 disposable email services in host_permissions; not explained by stated function of FB account management.
- brand impersonation store brand_mention.is_impersonation=true for Facebook; developer domain is gmail.com, confirmed_owner=false.
- free-webmail developer store zenius2009@gmail.com with no verified publisher badge; Reputation floor applies.
- privacy policy not scoped api scope_extension=false, data_collection=false, third_party_silence=true → +9.0 privacy pillar score.
- no CSP (MV3) manifest csp_present=false on MV3; no v2 +2.0 penalty applies but inline risk remains.
- ytsave.to external host crx Third-party YouTube download relay in js_external_hosts and host_permissions; unvetted service.
Permissions Breakdown
- storage low Stores local extension data; low risk in isolation.
- cookies high Can read/write cookies across all permitted origins including Facebook, TikTok, Microsoft.
- management high Can list, enable/disable other installed extensions — significant privilege escalation vector.
- tabs medium Can read URLs and titles of open tabs across all sites.
- downloads medium Can initiate and manage file downloads.
- webRequest high Can observe and intercept HTTP requests across host_permissions scope (FB, TikTok, Microsoft, etc.).
- declarativeNetRequest medium Can modify/block network requests declaratively; stacks with webRequest risk.
- host:facebook/instagram/messenger high Content scripts + cookies + webRequest on major social platforms enables session hijack.
- host:microsoft/live.com high Access to Microsoft auth domains; combined with cookies could capture auth tokens.
- host:tiktok/* + CDNs high Deep TikTok host access including content CDNs.
- host:temp-mail providers high Access to 6+ temp-mail services (moakt, fviainboxes, smvmail, mailngon, 5smail, tempmail.plus, tmail.tools-fb.com).
- host:ytsave.to medium Third-party YouTube download service; unclear data handling.
Pillar Scores
Permissions8.50
Reputation7.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:39
Listing SHA
9bd665556a99…
Force block
— not fired
Score recovered
no
Elapsed
—