Version submitted: 1.3.5
Submitted on: 2026-07-06
Current status: In review (still, as of 2026-07-15 — 9 days)
Extension name
机灵薯
Store ID
0RDCKFRLBLF2
CRX ID
egljbbepckippnbhombajooacmkldllp
Product ID
2106ef6c-0eee-4fe7-941e-5c123b8a683f
Question
Could you please share the current certification status of this submission and
an estimated completion date?
Context
This submission is the fix for the previous 1.2.2 Security (malware/PUA)
finding reported on version 1.3.4. The changes in 1.3.5 directly address that
finding:
- Removed the MAIN-world patching of
window.fetch / XMLHttpRequest on
creator.xiaohongshu.com that was previously used to read fan-data API
responses. The feature now performs same-origin requests to a fixed
allowlist of endpoints, and only after an explicit user action.
- (Already shipped in 1.2.8) Removed all
chrome.cookies usage and the
cookies permission from the manifest. The extension no longer reads,
stores, or transmits any third-party cookies.
Certification test credentials were provided in the submission's
"Notes for certification" field. I'm happy to re-share them privately if the
reviewer needs them.
If anything further is needed from my side to complete the security review,
I can provide it immediately.
xaverwu@outlook.com
Version submitted: 1.3.5
Submitted on: 2026-07-06
Current status: In review (still, as of 2026-07-15 — 9 days)
Extension name
机灵薯
Store ID
0RDCKFRLBLF2
CRX ID
egljbbepckippnbhombajooacmkldllp
Product ID
2106ef6c-0eee-4fe7-941e-5c123b8a683f
Question
Could you please share the current certification status of this submission and
an estimated completion date?
Context
This submission is the fix for the previous 1.2.2 Security (malware/PUA)
finding reported on version 1.3.4. The changes in 1.3.5 directly address that
finding:
window.fetch/XMLHttpRequestoncreator.xiaohongshu.comthat was previously used to read fan-data APIresponses. The feature now performs same-origin requests to a fixed
allowlist of endpoints, and only after an explicit user action.
chrome.cookiesusage and thecookiespermission from the manifest. The extension no longer reads,stores, or transmits any third-party cookies.
Certification test credentials were provided in the submission's
"Notes for certification" field. I'm happy to re-share them privately if the
reviewer needs them.
If anything further is needed from my side to complete the security review,
I can provide it immediately.
xaverwu@outlook.com