Is Presentation editor PPTWork for PPT slides safe?

High risk

PPTWork is high risk. Opening the popup makes it read your stored Redcoolmedia user key and GET stream.redcoolmedia.net/api/pptworkb-h.php. Evidence shows the popup expects XXXXX/YYYYY/ZZZZZ-delimited records, rendering returned URLs as clickable links.…

RedcoolMediav1.9.8Chrome Web Store
75Risk
Who publishes it

RedcoolMedia - 15 other listings from the same operator, 10 of them carrying a finding

What this publisher told the store about itself, and the other listings that told it the same thing.

Publisher
RedcoolMedia
Registered address
Europe Avenue, S/N, Pozuelo 28224, Spain

Same store account

15 other listings published from this account, 443k+ users between them. 10 of them carry a finding.

Shared hosts - 2 hostnames

Hostnames hardcoded in this extension that few other listings call. That can mean one operator behind both, and it can equally mean a small shared vendor, so it is context rather than a conclusion. Hosts that many listings call are left out: they are services, not connections.

stream.redcoolmedia.net
Also called by 4 other listings
redcoolmedia.net
Also called by 8 other listings

AI-generated. Findings may contain errors. Those marked Verified have been manually reviewed.

Publishers can request a review.

Findings

SeverityHIGH
ClassUNWANTED
TypeUnexpected
CWECWE-359
SourceAI SANDBOX

Popup retrieves your stored URL history from Redcoolmedia

Opening the popup makes it read your stored Redcoolmedia user key and GET stream.redcoolmedia.net/api/pptworkb-h.php.

Evidence shows the popup expects XXXXX/YYYYY/ZZZZZ-delimited records, rendering returned URLs as clickable links.

01EvidenceCAUSE EFFECT
What actually happens
You did this

You open the extension popup.

The manifest points the toolbar popup to index.html, which loads apar.js.

The extension did this

The popup asks Redcoolmedia for the URL history associated with your saved extension key.

It parses each returned record and displays the URLs as clickable entries.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://stream.redcoolmedia.net/api/pptworkb-h.php?u=usernameredcool
200 OK in the confirmed path; the popup parser expects XXXXX/YYYYY/ZZZZZ-delimited URL history records and renders them into the popup.
03EvidenceFIELD TABLE
Fields used to retrieve and display the saved history log
FieldValueWhy it matters
Your extension user key
A7b9K2mQ4z (illustrative 10-character key generated by the extension)This lets the remote service associate the returned history log with the same browser profile over time.
Returned page URL
https://sample-videos.com/download-sample-xls.phpEach returned URL can reveal a page that was previously associated with your extension user key.
History record delimiters
XXXXXhttps://sample-videos.com/download-sample-xls.phpYYYYYhttps://sample-videos.com/download-sample-xls.phpZZZZZThe popup treats the response as a list of URL records and extracts URL text from each record.
04EvidenceCODE COMPARE
The code that does this

The same stored key records URLs and retrieves the history log

What it actually does
Readable equivalent of the popup history retrieval
async function loadPopupHistory() {
  const record = await chrome.storage.local.get(["redcool_key"]);
  const settings = record.redcool_key || { usernameredcool: null, redcoolonline: null };
  const userKey = settings.usernameredcool || randomString(10);
  settings.usernameredcool = userKey;
  settings.redcoolonline = settings.redcoolonline || "1";
  await chrome.storage.local.set({ redcool_key: settings });

  if (settings.redcoolonline !== "1") {
    document.getElementById("urlbrowsed").innerHTML = "<p style='color: #000000;'>Scan disabled</p>";
    return;
  }

  const request = new XMLHttpRequest();
  request.open("GET", "https://stream.redcoolmedia.net/api/pptworkb-h.php?u=" + userKey, true);
  request.onload = function () {
    if (request.readyState !== 4 || request.status !== 200) {
      document.getElementById("urlbrowsed").innerHTML = "<p style='color: #000000;'>No URLs browsed yet</p>";
      return;
    }

    let remaining = request.responseText;
    while (remaining.indexOf("XXXXX") !== -1) {
      const record = remaining.substring(remaining.indexOf("XXXXX"), remaining.indexOf("ZZZZZ") + 5);
      const urlId = record.substring(record.indexOf("XXXXX") + 5, record.indexOf("YYYYY"));
      const displayUrl = record.substring(record.indexOf("YYYYY") + 5, record.indexOf("ZZZZZ"));
      const link = $("<a>").text("- Click to scan for files in the URL " + displayUrl).on("click", function () {
        detectfilesperurl(this.id);
      });
      link.attr("id", urlId);
      $("#urlbrowsed").append(link);
      $("#urlbrowsed").append("<br>");
      remaining = remaining.replace(record, "");
    }
  };
  request.send();
}
Readable equivalent of the URL-recording path that feeds the history log
async function recordVisitedUrl(url) {
  const record = await chrome.storage.local.get(["redcool_key"]);
  const settings = record.redcool_key || { usernameredcool: null, redcoolonline: null };
  const userKey = settings.usernameredcool || randomString(10);
  settings.usernameredcool = userKey;
  settings.redcoolonline = settings.redcoolonline || "1";
  await chrome.storage.local.set({ redcool_key: settings });

  if (settings.redcoolonline === "0") {
    return;
  }

  await fetch(
    "https://stream.redcoolmedia.net/api/pptworku-h.php?l=" +
      bin2hex(url) +
      "&hex=1&u=" +
      userKey
  );
}
05EvidenceTHIRD PARTY LIST
Remote service involved in the history lookup
  • stream.redcoolmedia.net

    Receives URL-recording requests and serves the popup endpoint that returns URL history records for the stored extension user key.

SeverityMEDIUM
ClassUNWANTED
TypeUnexpected
CWECWE-200
SourceAI SANDBOX

Popup URL scan sends selected browsing URLs to Redcoolmedia.

Clicking a link in the popup's URLs browsed section submits that URL to Redcoolmedia's stream endpoint for a file scan.

The browsing URL is encoded in the query string, and the returned HTML is shown in the popup.

01EvidenceCAUSE EFFECT
What actually happens
You did this

The user clicks a link in the popup's URLs browsed section.

The extension did this

The extension sends the selected browsing URL to the Redcoolmedia scan endpoint.

02EvidenceNETWORK CAPTURE
Captured request
GEThttps://stream.redcoolmedia.net/api/pptworkb-h-l.php
03EvidenceFIELD TABLE
Fields in the request
FieldValueWhy it matters
Selected browsing URL
https://example.com/presentation.html (illustrative)Identifies the page the user chose from the popup's browsing-history view for remote scanning.

What it can do

Permissions this extension asks for, as declared in version 1.9.8. Asking for a permission is not a finding on its own - it is what the extension can do if it chooses to.

  • Store data in your browser

    storage

  • See the address and title of every tab you have open

    tabs

Updated 30 September 2026glmfkanjkeedalikadkjlmijemmiknce