Is Cassou safe?
Cassou accepts a postMessage from any sender and writes its cookie field into the page's cookies without checking the message's origin.
When Vinted shows a Cloudflare/captcha challenge, Cassou opens a recovery iframe and listens for a reply on window.postMessage. It never checks who the message came from, so any frame or window with a reference to the Vinted tab can send a fake reply and have its cookie value written directly into the tab's cookies, followed by a page reload. This affects local browser cookies on the vinted.* site and does not send any data to an outside server.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
Who publishes itCassou - no other listings under this identity, 4 shared hostnames
Cassou - no other listings under this identity, 4 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 4 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.