Music Mode for YouTube™
abbpaepbpakcpipajigmlpnhlnbennna
Risk Score
4.23
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope to this extension; data practices completely undisclosed.
- Brand impersonation: YouTube™ trademark in name without verified ownership; developer is gmail-only individual.
- Free-webmail developer (gmail) with no business domain; low accountability and transfer risk.
- install_url_hijack: onInstalled opens pages/options.html — minor but indicative of low-hygiene practices.
- DOM-XSS sink (innerHTML from variable) with no CSP; exploitable if input ever reaches user-controlled data.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; YouTube™ trademark used; developer is gmail individual, not YouTube/Google.
- generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email thunderarea.np@gmail.com; no business domain; domain_age_ct not queried.
- install_url_hijack crx install_url_hijack=true; onInstalled opens pages/options.html (internal page, low severity but present).
- dom_xss_sink crx dom_sink_innerhtml_userctrl in content_popup/content.js; no CSP present; DOM-XSS risk on YouTube pages.
- no_csp manifest content_security_policy is null; MV3 has strict defaults but no explicit CSP increases XSS sink risk.
- featured_by_google store is_featured_by_google=true; partially offsets brand/reputation risk.
- installs_reach store 70,000 installs on YouTube-scoped content scripts; blast radius limited to YouTube domains.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata; enables tracking of visited YouTube pages.
- declarativeNetRequest medium Can block/redirect network requests; scoped to YouTube domains here, moderate risk.
- storage low Local data persistence only; standard for storing user preferences.
- unlimitedStorage low Removes storage quota cap; low direct harm but could store large amounts of data.
- content_scripts: *://www.youtube.com/* (and related) medium Runs JS on all YouTube pages; scoped to YouTube only, matches stated function.
Pillar Scores
Permissions2.30
Reputation7.00
Network0.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA
f382f59f2b21…
Force block
— not fired
Score recovered
no
Elapsed
24.8s