Awesome SAML Tracer
pilkjgooejhajccieiebbihilnclbpej
Risk Score
3.32
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- webRequest + <all_urls>: intercepts all HTTP traffic across every site, high capability for a small-install dev tool.
- Developer email is free webmail (outlook.com) with no named developer and no verified business domain.
- Privacy policy scoped to extension but admits third-party sharing without specifying recipients.
- No CSP declared (MV3 default applies) combined with innerHTML DOM-XSS sink in popup.js.
- External JS hosts include ko-fi.com and lucide.dev — third-party resources loaded outside dev's own domain.
Evidence
- webRequest + <all_urls> manifest HIGH permission pair: can read/block every network request across all URLs.
- free_webmail_developer store Developer email jake.segers@outlook.com; no developer name listed; no business domain.
- verified_publisher store Verified publisher badge present; partially mitigates identity concern.
- dom_sink_innerhtml_userctrl crx popup/popup.js: infoBar.innerHTML = html — DOM-XSS sink; csp_present==false amplifies.
- third_party_sharing_admitted api Privacy policy: scope_extension=true, data_collection=false, third_party_sharing=true, no retention.
- external_js_hosts crx Extension references ast-web.pages.dev, ko-fi.com, lucide.dev — 3 distinct external domains.
- no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries detected.
- operator_cluster api sibling_count=0; no operator cluster risk.
Permissions Breakdown
- webRequest high Intercepts all network requests across every site visited; paired with <all_urls> raises capability significantly.
- storage low Local data persistence; low risk in isolation.
- tabs medium Access to tab URLs and metadata; combined with webRequest increases surveillance surface.
- downloads medium Can initiate/manage file downloads; relevant for SAML export feature but adds capability.
- <all_urls> high Broad host access enabling webRequest to intercept traffic on every site.
Pillar Scores
Permissions5.80
Reputation5.50
Network3.00
Webstore0.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-17 07:26
Listing SHA
ed769c807a34…
Force block
— not fired
Score recovered
no
Elapsed
—