Better DeepSeek
aabiopennjmopfippagcalmkdjlepdhh
Risk Score
6.77
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- <all_urls> host permission plus CDN/pyscript.net permissions enable remote code loading across every site.
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Brand impersonation: 'deepseek' mentioned, developer is not confirmed owner and is not verified publisher.
- sandbox.js uses new Function() constructor enabling arbitrary code execution from string input.
- content.js has innerHTML DOM-XSS sink; CSP sandbox allows unsafe-eval/unsafe-inline amplifying risk.
Evidence
- all_urls + CDN host permissions manifest <all_urls>, cdn.jsdelivr.net, pyscript.net declared — broad reach enabling remote JS execution.
- brand impersonation store brand_mention.is_impersonation=true, confirmed_owner=false, not verified publisher.
- generic privacy policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- sandbox CSP unsafe-eval crx sandbox CSP allows unsafe-eval and unsafe-inline; amplifies function_constructor risk in sandbox.js.
- function_constructor in sandbox.js crx new Function() used on string input — arbitrary code execution risk.
- 10 external JS hosts crx js_external_hosts includes raw.githubusercontent.com, svelte.dev, stuartk.com, stuk.github.io, example.com.
- maintenance unknown store last_updated is empty; months_since_update null — cannot verify currency.
- AI extension processing page content store Content script on chat.deepseek.com with broad host access and AI-enhancement description.
Permissions Breakdown
- host: https://chat.deepseek.com/* medium Scoped to DeepSeek chat; matches stated function.
- host: https://codeload.github.com/* medium GitHub code download endpoint; plausible for code tools but expands attack surface.
- host: https://cdn.jsdelivr.net/* high Remote CDN host permission — could load arbitrary JS from jsDelivr at runtime.
- host: https://pyscript.net/* high Remote Python-runtime CDN; arbitrary code execution surface.
- host: <all_urls> high Unrestricted host access across every site the user visits.
- storage low Local key-value storage only; no cross-origin data access.
Pillar Scores
Permissions7.50
Reputation7.00
Network5.00
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:14
Listing SHA
5dc7806fdf41…
Force block
— not fired
Score recovered
no
Elapsed
30.3s