Is Cassou safe?

Low risk

Cassou accepts a postMessage from any sender and writes its cookie field into the page's cookies without checking the message's origin.

When Vinted shows a Cloudflare/captcha challenge, Cassou opens a recovery iframe and listens for a reply on window.postMessage. It never checks who the message came from, so any frame or window with a reference to the Vinted tab can send a fake reply and have its cookie value written directly into the tab's cookies, followed by a page reload. This affects local browser cookies on the vinted.* site and does not send any data to an outside server.

Part of this rating comes from analysis signals we haven't published as detailed findings yet.

Cassouv1.1.0Chrome Web Store
20Risk
Who publishes it

Cassou - no other listings under this identity, 4 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Cassou
Declared legal entity
Cassou

Shared hosts - 4 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

vinted.ie
Also called by 2 other listings, including Asify
vinted.ro
Also called by 2 other listings, including Asify
vinted.hu
Also called by 3 other listings, including Asify
vinted.sk
Also called by 4 other listings, including Asify, Vinteer - Back-office CRM & comptabilité pour vendeurs Vinted

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Updated 30 September 2026fplhapliabhckmadcmkkpaoflmadpidp