Is Presentation editor PPTWork for PPT slides safe?
PPTWork is high risk. Opening the popup makes it read your stored Redcoolmedia user key and GET stream.redcoolmedia.net/api/pptworkb-h.php. Evidence shows the popup expects XXXXX/YYYYY/ZZZZZ-delimited records, rendering returned URLs as clickable links.…
Who publishes itRedcoolMedia - 15 other listings from the same operator, 10 of them carrying a finding
RedcoolMedia - 15 other listings from the same operator, 10 of them carrying a finding
What this publisher told the store about itself, and the other listings that told it the same thing.
Same store account
15 other listings published from this account, 443k+ users between them. 10 of them carry a finding.
Shared hosts - 2 hostnames
Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.
AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.
Publishers can request a review.
Findings
Popup retrieves your stored URL history from Redcoolmedia
Opening the popup makes it read your stored Redcoolmedia user key and GET stream.redcoolmedia.net/api/pptworkb-h.php.
Evidence shows the popup expects XXXXX/YYYYY/ZZZZZ-delimited records, rendering returned URLs as clickable links.
You open the extension popup.
The manifest points the toolbar popup to index.html, which loads apar.js.
The popup asks Redcoolmedia for the URL history associated with your saved extension key.
It parses each returned record and displays the URLs as clickable entries.
| Field | Value | Why it matters | |
|---|---|---|---|
Your extension user key | A7b9K2mQ4z (illustrative 10-character key generated by the extension) | This lets the remote service associate the returned history log with the same browser profile over time. | |
Returned page URL | https://sample-videos.com/download-sample-xls.php | Each returned URL can reveal a page that was previously associated with your extension user key. | |
History record delimiters | XXXXXhttps://sample-videos.com/download-sample-xls.phpYYYYYhttps://sample-videos.com/download-sample-xls.phpZZZZZ | The popup treats the response as a list of URL records and extracts URL text from each record. |
The same stored key records URLs and retrieves the history log
async function loadPopupHistory() {
const record = await chrome.storage.local.get(["redcool_key"]);
const settings = record.redcool_key || { usernameredcool: null, redcoolonline: null };
const userKey = settings.usernameredcool || randomString(10);
settings.usernameredcool = userKey;
settings.redcoolonline = settings.redcoolonline || "1";
await chrome.storage.local.set({ redcool_key: settings });
if (settings.redcoolonline !== "1") {
document.getElementById("urlbrowsed").innerHTML = "<p style='color: #000000;'>Scan disabled</p>";
return;
}
const request = new XMLHttpRequest();
request.open("GET", "https://stream.redcoolmedia.net/api/pptworkb-h.php?u=" + userKey, true);
request.onload = function () {
if (request.readyState !== 4 || request.status !== 200) {
document.getElementById("urlbrowsed").innerHTML = "<p style='color: #000000;'>No URLs browsed yet</p>";
return;
}
let remaining = request.responseText;
while (remaining.indexOf("XXXXX") !== -1) {
const record = remaining.substring(remaining.indexOf("XXXXX"), remaining.indexOf("ZZZZZ") + 5);
const urlId = record.substring(record.indexOf("XXXXX") + 5, record.indexOf("YYYYY"));
const displayUrl = record.substring(record.indexOf("YYYYY") + 5, record.indexOf("ZZZZZ"));
const link = $("<a>").text("- Click to scan for files in the URL " + displayUrl).on("click", function () {
detectfilesperurl(this.id);
});
link.attr("id", urlId);
$("#urlbrowsed").append(link);
$("#urlbrowsed").append("<br>");
remaining = remaining.replace(record, "");
}
};
request.send();
}async function recordVisitedUrl(url) {
const record = await chrome.storage.local.get(["redcool_key"]);
const settings = record.redcool_key || { usernameredcool: null, redcoolonline: null };
const userKey = settings.usernameredcool || randomString(10);
settings.usernameredcool = userKey;
settings.redcoolonline = settings.redcoolonline || "1";
await chrome.storage.local.set({ redcool_key: settings });
if (settings.redcoolonline === "0") {
return;
}
await fetch(
"https://stream.redcoolmedia.net/api/pptworku-h.php?l=" +
bin2hex(url) +
"&hex=1&u=" +
userKey
);
}- stream.redcoolmedia.net
Receives URL-recording requests and serves the popup endpoint that returns URL history records for the stored extension user key.
Popup URL scan sends selected browsing URLs to Redcoolmedia.
Clicking a link in the popup's URLs browsed section submits that URL to Redcoolmedia's stream endpoint for a file scan.
The browsing URL is encoded in the query string, and the returned HTML is shown in the popup.
The user clicks a link in the popup's URLs browsed section.
The extension sends the selected browsing URL to the Redcoolmedia scan endpoint.
| Field | Value | Why it matters | |
|---|---|---|---|
Selected browsing URL | https://example.com/presentation.html (illustrative) | Identifies the page the user chose from the popup's browsing-history view for remote scanning. |
What it can do
Permissions this extension asks for, as declared in version 1.9.8. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.
Store data in your browser
storage
See the address and title of every tab you have open
tabs