This extension shows critical risk indicators. It requests highly sensitive permissions combined with suspicious code patterns. Proceed with extreme caution.
Based on 6 permissions including high-risk ones, 25 code findings, 1 dangerous combination.
Extension intercepts network traffic and sends data externally — potential man-in-the-middle behavior.
This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.
Resolved from __MSG_* i18n placeholders:
Description: Discover the best coupons at your favorite online shops. With just a click, enjoy seamless checkout with automatic savings.
JavaScript files are accessible to ALL websites. Any page can load and interact with these scripts, enabling web→extension attacks.
Web-accessible resources use <all_urls> or wildcard patterns, exposing resources to every website.
Content script matches <all_urls>, executing on every website the user visits.
24 indicators of compromise found