GIF Maker | Gifzz
acmfeacjdhhlkkiedpfkkhbnddjanphf
Risk Score
4.66
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Privacy policy fetched but scope_extension=false AND third_party_sharing=true: policy admits sharing without scoping to this extension → Privacy=10.0
- <all_urls> host permission combined with tabCapture allows screen/audio capture across all sites
- new Function() constructor found in 6 JS files with no CSP; MV3 but no content_security_policy declared
- Developer email is free webmail (gmail) with no developer name and no verified business identity
- Content scripts injected into major social platforms (Discord, Twitter/X, Facebook, Telegram, Messenger) with broad <all_urls> fallback
Evidence
- broad_host_plus_tabCapture manifest host_permissions=[<all_urls>] + tabCapture declared; can capture any tab's screen/audio content.
- no_csp crx content_security_policy is null; no CSP protection on MV3 extension with function_constructor findings.
- privacy_policy_scope_fail api Policy fetched (23 KB) but scope_extension=false and third_party_sharing=true → D-clause: +10.0 privacy.
- function_constructor_pervasive crx new Function() found in 6 of 11 JS files; no CSP amplifies risk per v3 FIX B logic.
- free_webmail_no_devname store developer_name='', developer_email='alluka1478@gmail.com'; free webmail + no name boosts Reputation.
- content_scripts_social_platforms manifest Content scripts match Discord, Twitter/X, Facebook, Messenger, Telegram plus <all_urls> fallback.
- verified_publisher store verified_publisher=true; -1.5 reputation discount applied (capped at -1.0 due to no monetization/affiliate issues).
- maintenance_3_6_months store months_since_update=6; borderline 3-6 month band → +1.5 maintenance score.
Permissions Breakdown
- storage low Standard local data storage; low standalone risk.
- tabCapture high Captures live tab audio/video; high privacy impact for a GIF maker.
- offscreen medium Creates off-screen documents; can hide processing from user view.
- <all_urls> (host_permission) high Broad host access enables content scripts on every site; paired with tabCapture this is a significant risk surface.
Pillar Scores
Permissions7.50
Reputation6.50
Network4.00
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA
a20d3af2d07b…
Force block
— not fired
Score recovered
no
Elapsed
25.1s