Is Email Tracker + Pixelblock Detector & Blocker safe?
Email Tracker is high risk. Rules 5002-5005 strip CSP and CSP-Report-Only headers on outlook.live.com, outlook.office.com, mail.live.com, and outlook.office365.com. CSP limits page loads; removing it lets injected content, including its own tracking pixels, load.
Who publishes itEmail Tracker - no other listings under this identity, 4 shared hostnames
Email Tracker - no other listings under this identity, 4 shared hostnames
What this publisher told the store about itself, and the other listings that told it the same thing.
Shared hosts - 4 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
CSP Headers Stripped from Outlook Webmail Without Disclosure
Rules 5002-5005 strip CSP and CSP-Report-Only headers on outlook.live.com, outlook.office.com, mail.live.com, and outlook.office365.com.
CSP limits page loads; removing it lets injected content, including its own tracking pixels, load.
You open Outlook webmail, any page on outlook.live.com, outlook.office.com, mail.live.com, or outlook.office365.com.
The extension removes the Content-Security-Policy and Content-Security-Policy-Report-Only headers from Outlook's HTTP response before your browser processes them.
This happens on every page load, including the main frame and any sub-frames, with no visible indication in the Outlook UI.
The four declarativeNetRequest rules that remove CSP headers from Outlook domains.
// For every HTTP response from Outlook webmail (main page or embedded frames), // Chrome's built-in rule engine removes these two security headers before // the browser sees them: // // Content-Security-Policy — the primary CSP header // Content-Security-Policy-Report-Only — the reporting-mode CSP header // // Affected domains: // outlook.live.com (Hotmail / Outlook.com) // outlook.office.com (Microsoft 365 OWA) // mail.live.com (legacy Hotmail) // outlook.office365.com (Office 365 OWA) // // Effect: Outlook's CSP policy — which restricts which scripts and images // the page may load — is no longer enforced in the user's browser. // The extension's own content scripts and any injected tracking pixel <img> // tags can therefore load external resources that Outlook's CSP would // otherwise have blocked.
- outlook.live.com
Microsoft Outlook.com webmail (Hotmail). CSP headers removed on all main_frame and sub_frame responses.
- outlook.office.com
Microsoft 365 Outlook Web Access. CSP headers removed on all main_frame and sub_frame responses.
- mail.live.com
Legacy Microsoft Hotmail domain. CSP headers removed on all main_frame and sub_frame responses.
- outlook.office365.com
Office 365 OWA endpoint. CSP headers removed on all main_frame and sub_frame responses.
Reads the extension's declarativeNetRequest rules file and reports which rules remove Content-Security-Policy headers. Run it to verify the claim from the extension source on disk.
#!/usr/bin/env node
// check-csp-strip-rules.js
// Verifies that Email Tracker + Pixelblock contains CSP-stripping
// declarativeNetRequest rules targeting Outlook webmail domains.
//
// Usage: node check-csp-strip-rules.js <path-to-extracted-extension>
// Example: node check-csp-strip-rules.js ./bnompdfnhdbgdaoanapncknhmckenfog/extracted
const fs = require('fs');
const path = require('path');
const extDir = process.argv[2];
if (!extDir) {
console.error('Usage: node check-csp-strip-rules.js <path-to-extracted-extension>');
process.exit(1);
}
const rulesPath = path.join(extDir, 'declarative_net_request_rules.json');
if (!fs.existsSync(rulesPath)) {
console.error('ERROR: declarative_net_request_rules.json not found at', rulesPath);
process.exit(1);
}
const rules = JSON.parse(fs.readFileSync(rulesPath, 'utf8'));
const cspRules = rules.filter(rule =>
rule.action &&
rule.action.type === 'modifyHeaders' &&
Array.isArray(rule.action.responseHeaders) &&
rule.action.responseHeaders.some(h =>
h.header === 'content-security-policy' && h.operation === 'remove'
)
);
if (cspRules.length === 0) {
console.log('RESULT: No CSP-stripping rules found.');
process.exit(0);
}
console.log(`RESULT: Found ${cspRules.length} CSP-stripping rule(s):\n`);
for (const rule of cspRules) {
const headers = rule.action.responseHeaders.map(h => h.header).join(', ');
console.log(` Rule ID : ${rule.id}`);
console.log(` URL filter : ${rule.condition.urlFilter}`);
console.log(` Resource types: ${rule.condition.resourceTypes.join(', ')}`);
console.log(` Headers removed: ${headers}`);
console.log();
}
console.log('These rules cause Chrome to remove Content-Security-Policy headers');
console.log('from all Outlook webmail responses before the page renders.');
- 1Unpack the extension CRX (or download source from Chrome Web Store).
- 2Run: node check-csp-strip-rules.js ./extracted-extension-dir.
- 3The script prints each rule that removes Content-Security-Policy headers and the domain it targets.