Cleaner - history & cache clean
pooaemmkohlphkekccfajnbcokjlbehk
Risk Score
6.61
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- cookies + *://*/* host access enables reading/exfiltrating all browser cookies from any site
- Uninstall AND install URL hijack both present — classic traffic-monetization/redirect pattern
- Privacy policy is generic Google account policy — does not scope to this extension at all (D-rule: admits data collection + 3rd-party sharing)
- Developer uses free Hotmail email with no verified publisher badge and generic 'Smart extension' name
- jQuery 3.4.1 bundled with two medium XSS CVEs (CVE-2020-11022, CVE-2020-11023); no CSP to mitigate
Evidence
- cookies + *://*/* host permissions manifest cookies HIGH permission paired with broad host access *://*/* — ×1.2 multiplier applied; can exfiltrate all cookies.
- uninstall_url_hijack + install_url_hijack both true crx Both onInstall and uninstall URL hijacks active — webstore +3.0 (uninstall) +2.0 (install) traffic-monetization signals.
- Privacy policy is generic Google account policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D-rule).
- Free webmail developer email store cleaner_help@hotmail.com — free webmail, no verified publisher, no business domain; reputation floor applies.
- jQuery 3.4.1 with CVE-2020-11022 and CVE-2020-11023 crx Two medium-severity XSS CVEs; fixed_in 3.5.0; no CSP present to mitigate DOM sinks.
- External JS host smartcleaner.online crx Extension contacts smartcleaner.online — developer-controlled but not a recognized domain; adds network surface.
- is_featured_by_google = true store Google Featured badge applies -2.0 reputation discount but does not override hotmail+no-verified-publisher risk floor.
- No CSP present (csp_present=false) on MV3 manifest No content_security_policy declared; CVE XSS libs have no mitigation layer.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Stores extension settings; low standalone risk.
- browsingData high Core function but grants ability to delete all browser history, cookies, cache.
- tabs medium Can read tab URLs and titles; paired with broad host access raises risk.
- cookies high Can read/write/delete cookies for any domain; HIGH risk especially with *://*/*.
- alarms low Schedules background tasks; minimal standalone risk.
- *://*/* high Broad host access paired with cookies = critical capability multiplier.
Pillar Scores
Permissions8.00
Reputation6.00
Network4.00
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:58
Listing SHA
026598d0a2da…
Force block
— not fired
Score recovered
no
Elapsed
—