Is Email Tracker + Pixelblock Detector & Blocker safe?

High risk

Email Tracker is high risk. Rules 5002-5005 strip CSP and CSP-Report-Only headers on outlook.live.com, outlook.office.com, mail.live.com, and outlook.office365.com. CSP limits page loads; removing it lets injected content, including its own tracking pixels, load.

Email Trackerv5.0.60Chrome Web Store
75Risk
Who publishes it

Email Tracker - no other listings under this identity, 4 shared hostnames

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
Email Tracker
Declared legal entity
Email Tracker
Registered address
472 Amherst St, Suite 717196, Nashua, NH 03063, US

Shared hosts - 4 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

bitli.pro
Also called by 1 other listing: Email Tracker + Tracking Pixel Blocker
bitt.site
Also called by 1 other listing: Email Tracker + Tracking Pixel Blocker
geoiptool.com
Also called by 1 other listing: Email Tracker + Tracking Pixel Blocker
shortened-link.com
Also called by 1 other listing: Email Tracker + Tracking Pixel Blocker

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

CSP Headers Stripped from Outlook Webmail Without Disclosure

Rules 5002-5005 strip CSP and CSP-Report-Only headers on outlook.live.com, outlook.office.com, mail.live.com, and outlook.office365.com.

CSP limits page loads; removing it lets injected content, including its own tracking pixels, load.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open Outlook webmail, any page on outlook.live.com, outlook.office.com, mail.live.com, or outlook.office365.com.

The extension did this

The extension removes the Content-Security-Policy and Content-Security-Policy-Report-Only headers from Outlook's HTTP response before your browser processes them.

This happens on every page load, including the main frame and any sub-frames, with no visible indication in the Outlook UI.

02EvidenceCODE COMPARE
The code that does this

The four declarativeNetRequest rules that remove CSP headers from Outlook domains.

What it actually does
What these four rules do in plain terms
// For every HTTP response from Outlook webmail (main page or embedded frames),
// Chrome's built-in rule engine removes these two security headers before
// the browser sees them:
//
//   Content-Security-Policy            — the primary CSP header
//   Content-Security-Policy-Report-Only — the reporting-mode CSP header
//
// Affected domains:
//   outlook.live.com        (Hotmail / Outlook.com)
//   outlook.office.com      (Microsoft 365 OWA)
//   mail.live.com           (legacy Hotmail)
//   outlook.office365.com   (Office 365 OWA)
//
// Effect: Outlook's CSP policy — which restricts which scripts and images
// the page may load — is no longer enforced in the user's browser.
// The extension's own content scripts and any injected tracking pixel <img>
// tags can therefore load external resources that Outlook's CSP would
// otherwise have blocked.
03EvidenceTHIRD PARTY LIST
Domains whose CSP headers are stripped:
  • outlook.live.com

    Microsoft Outlook.com webmail (Hotmail). CSP headers removed on all main_frame and sub_frame responses.

  • outlook.office.com

    Microsoft 365 Outlook Web Access. CSP headers removed on all main_frame and sub_frame responses.

  • mail.live.com

    Legacy Microsoft Hotmail domain. CSP headers removed on all main_frame and sub_frame responses.

  • outlook.office365.com

    Office 365 OWA endpoint. CSP headers removed on all main_frame and sub_frame responses.

04EvidenceARTIFACT
Check if you're affected

Reads the extension's declarativeNetRequest rules file and reports which rules remove Content-Security-Policy headers. Run it to verify the claim from the extension source on disk.

RequiresNode.js 14+
check-csp-strip-rules.js · js
#!/usr/bin/env node
// check-csp-strip-rules.js
// Verifies that Email Tracker + Pixelblock contains CSP-stripping
// declarativeNetRequest rules targeting Outlook webmail domains.
//
// Usage: node check-csp-strip-rules.js <path-to-extracted-extension>
// Example: node check-csp-strip-rules.js ./bnompdfnhdbgdaoanapncknhmckenfog/extracted

const fs = require('fs');
const path = require('path');

const extDir = process.argv[2];
if (!extDir) {
  console.error('Usage: node check-csp-strip-rules.js <path-to-extracted-extension>');
  process.exit(1);
}

const rulesPath = path.join(extDir, 'declarative_net_request_rules.json');
if (!fs.existsSync(rulesPath)) {
  console.error('ERROR: declarative_net_request_rules.json not found at', rulesPath);
  process.exit(1);
}

const rules = JSON.parse(fs.readFileSync(rulesPath, 'utf8'));

const cspRules = rules.filter(rule =>
  rule.action &&
  rule.action.type === 'modifyHeaders' &&
  Array.isArray(rule.action.responseHeaders) &&
  rule.action.responseHeaders.some(h =>
    h.header === 'content-security-policy' && h.operation === 'remove'
  )
);

if (cspRules.length === 0) {
  console.log('RESULT: No CSP-stripping rules found.');
  process.exit(0);
}

console.log(`RESULT: Found ${cspRules.length} CSP-stripping rule(s):\n`);
for (const rule of cspRules) {
  const headers = rule.action.responseHeaders.map(h => h.header).join(', ');
  console.log(`  Rule ID      : ${rule.id}`);
  console.log(`  URL filter   : ${rule.condition.urlFilter}`);
  console.log(`  Resource types: ${rule.condition.resourceTypes.join(', ')}`);
  console.log(`  Headers removed: ${headers}`);
  console.log();
}
console.log('These rules cause Chrome to remove Content-Security-Policy headers');
console.log('from all Outlook webmail responses before the page renders.');
How to run it
  1. 1
    Unpack the extension CRX (or download source from Chrome Web Store).
  2. 2
    Run: node check-csp-strip-rules.js ./extracted-extension-dir.
  3. 3
    The script prints each rule that removes Content-Security-Policy headers and the domain it targets.
Updated 30 September 2026bnompdfnhdbgdaoanapncknhmckenfog