ReAPI Extension

ReAPI Extension

ID: afgjkfoekcdikiaiglomnpcihlpnnbnn

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Active
Version
0.0.3
Size
0.37 MB
Rating
0.0/5
Reviews
0
Users
29
Type
Extension
Updated
Apr 1, 2025
Category
Developer tools
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
Yes

Publisher Contextual Analysis

Trusted
Author
peisongoView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
2
Active
1
Obsolete
1
Listed
2
Unlisted
0
Total Users
267
Screenshot 1
Screenshot 2

Bypass CORS when using ReAPI.com explorer.

This is a ReAPI.com extension used to by pass Chrome CORS when debugging Rest APIs in ReAPI explorer.

Item
Type
Severity
Description
webRequest
Permission
Critical
This permission enables the extension to monitor and analyze all web requests made by the browser. Rated Critical because it can observe all network traffic including sensitive data, track browsing behavior, and gather authentication tokens.
declarativeNetRequest
Permission
Critical
This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites.
*://*/*
Host
Critical
Broad host access — the extension can read/modify content on every website.
Broad Host Permissions
Risk Factor
High
This extension has broad host permissions allowing it to access many or all websites.
declarativeNetRequestFeedback
Permission
Medium
This permission provides network request modification logs. Rated Medium because it can monitor network request changes and debug traffic modifications.
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.

The bundled manifest declares webRequest, declarativeNetRequestFeedback, storage, and tabs — none of which appear in the CWS-published manifest (which lists only cookies and declarativeNetRequest). webRequest in particular grants real-time interception of all browser traffic, far exceeding what the CORS-helper purpose requires. The mismatch between what Google shows users in the store listing and what is actually installed is itself a high-severity red flag under the schema's manifest-mismatch rule.

manifest.json (Line 33)
{  "permissions": [    "webRequest",    "declarativeNetRequest",    "declarativeNetRequestFeedback",    "storage",    "tabs"  ],  "declarative_net_request": {    "rule_resources": []  }}

A static rule file exists that would inject a non-standard synthetic header A6666: 69699696 into every XHR/WebTransport response with no domain condition. While the manifest's rule_resources array is empty so this file is not currently loaded, its presence alongside an undisclosed webRequest permission and a publisher with a 100% malware rate for other extensions is anomalous. The header value has no apparent legitimate purpose and could serve as an extension fingerprint readable by any page script.

rules_1.json (Line 1)
[  {    "id": 1,    "priority": 1,    "action": {      "type": "modifyHeaders",      "responseHeaders": [        {          "header": "Access-Control-Allow-Origin",          "operation": "set",          "value": "*"        },        {          "header": "A6666",          "operation": "set",          "value": "69699696"        }      ]    },    "condition": {      "resourceTypes": [        "xmlhttprequest",        "webtransport",        "other"      ]    }  }]

By severity

Critical0
High1
Medium1
Low0

Versions scanned

Showing 1 of 22 scanned versions with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
0.0.32

Files with findings

2 distinct paths — top paths by unique finding count:

  • manifest.json1
  • rules_1.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Other
high
manifest.json (line 33)The bundled manifest declares webRequest, declarativeNetRequestFeedback, storage, and tabs — none of which appear in the CWS-published manifest (which lists only cookies and declarativeNetRequest). webRequest in parti…
2Other
medium
rules_1.json (line 1)A static rule file exists that would inject a non-standard synthetic header A6666: 69699696 into every XHR/WebTransport response with no domain condition. While the manifest's rule_resources array is empty so this fil…
URLs
35
IPv4
65
IPv6
1

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

clients2.google.com/service/update2/crxhttps://clients2.google.com/service/update2/crx
tailwindcss.com/n*//*/n1.https://tailwindcss.com\n*//*\n1.
github.com/mozdevs/cssremedy/issues/4https://github.com/mozdevs/cssremedy/issues/4
github.com/tailwindcss/tailwindcss/pull/116https://github.com/tailwindcss/tailwindcss/pull/116
bugzilla.mozilla.org/show_bug.cgihttps://bugzilla.mozilla.org/show_bug.cgi?id=190655
bugs.chromium.org/p/chromium/issues/detailhttps://bugs.chromium.org/p/chromium/issues/detail?id=999088,
bugs.webkit.org/show_bug.cgihttps://bugs.webkit.org/show_bug.cgi?id=201297
bugs.chromium.org/p/chromium/issues/detailhttps://bugs.chromium.org/p/chromium/issues/detail?id=935729,
bugs.webkit.org/show_bug.cgihttps://bugs.webkit.org/show_bug.cgi?id=195016
github.com/mozilla/gecko-dev/blob/2f9eacd9d3d995c937b4251a5557d95d494c9be1/layout/style/res/forms.csshttps://github.com/mozilla/gecko-dev/blob/2f9eacd9d3d995c937b4251a5557d95d494c9be1/layout/style/res/forms.css#L728-L737
Showing 1 to 10 of 40 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

1.2.3.4
IPv4
-
3.1.5.3
IPv4
-
7.2.2.5
IPv4
-
125.125.221.125
IPv4
-
125.125.22.125
IPv4
-
11.11.232.224
IPv4
-
75.21.24.142
IPv4
-
14.135.25.24
IPv4
-
1.42.71.71
IPv4
-
15.97.105.31
IPv4
-
7.25.91.91
IPv4
-
25.72.94.94
IPv4
-
4.5.3.8
IPv4
-
1.3.8.3
IPv4
-
3.1.6.3
IPv4
-
8.6.2.3
IPv4
-
6.1.2.1
IPv4
-
3.2.5.4
IPv4
-
1.1.1.3
IPv4
-
2.13.71.71
IPv4
-
213.209.3.33
IPv4
-
119.168.246.231
IPv4
-
89.6.174.165
IPv4
-
1.19.79.45
IPv4
-
103.152.2.24
IPv4
-
32.127.134.23
IPv4
-
18.11.37.11
IPv4
-
1.2.83.51
IPv4
-
121.216.223.35
IPv4
-
32.15.5.5
IPv4
-
16.11.47.47
IPv4
-
24.55.75.75
IPv4
-
4.21.71.71
IPv4
-
122.177.195.25
IPv4
-
153.143.242.21
IPv4
-
22.14.6.6
IPv4
-
16.22.73.73
IPv4
-
25.14.52.52
IPv4
-
11.22.48.48
IPv4
-
4.4.93.93
IPv4
-
1.3.54.81
IPv4
-
2.48.7.7
IPv4
-
22.128.46.22
IPv4
-
9.34.41.41
IPv4
-
104.14.186.159
IPv4
-
152.74.184.168
IPv4
-
13.136.195.12
IPv4
-
108.104.213.185
IPv4
-
11.153.188.242
IPv4
-
109.149.85.85
IPv4
-
12.11.237.172
IPv4
-
114.143.21.242
IPv4
-
12.112.25.117
IPv4
-
164.203.64.64
IPv4
-
36.125.135.244
IPv4
-
115.13.198.26
IPv4
-
2.61.61.52
IPv4
-
13.46.38.38
IPv4
-
118.123.245.237
IPv4
-
157.175.157.32
IPv4
-
6.46.71.71
IPv4
-
19.2.19.52
IPv4
-
217.103.44.229
IPv4
-
103.228.155.48
IPv4
-
24.32.7.7
IPv4
-
1:2:3:4:5:6:7:8
IPv6
-
Showing 1 to 66 of 70 rows
Rows per page:
Showing 1 to 10 of 30 rows
Rows per page:

Code Diff

Compare extension code between any two versions.

0 changed files (scanned top 25 shared text files)

No comparable text files found between these versions.

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.