Is Cents Per Point Calculator safe?
Cents Per Point Calculator ships an unused test file containing a hardcoded Hilton session token, but nothing in the extension loads it.
The installed extension only runs scripts/hyatt.js, bonvoy.js, hilton.js and jblu.js on the airline/hotel booking pages named in its manifest. A separate file, test2.js, is bundled inside the package but is not referenced by the manifest or any other script, so it never executes after install. That dead file hardcodes an authorization bearer token and visitor/session identifiers that appear to have been captured from a real Hilton.com session during development, along with a fetch() call to www.hilton.com/graphql/customer.
Part of this rating comes from analysis signals we haven't published as detailed findings yet.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.