Phrasely - ChatGPT Writing Tool
adococdejjckhckfebefppmpefghoilg
Risk Score
5.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Content script runs on <all_urls> — can read/modify page content on every site visited, despite only 'activeTab' in permissions[].
- Privacy policy admits data collection AND third-party sharing but is not scoped to this extension (generic policy).
- ChatGPT brand impersonation by unverified gmail developer with no developer name listed.
- No CSP on MV3 extension with external host (editor.phrasely.app) — no header-level script constraint.
- 19 months since last update; stale AI tool with broad content-script reach.
Evidence
- content_scripts_matches=<all_urls> manifest Content script injected on all URLs despite narrow declared permissions[] — effective broad host access.
- privacy_policy: data_collection+third_party_sharing+no_extension_scope api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
- brand_mention impersonation store brand_mention.is_impersonation=true for 'chatgpt'; developer is gmail user, not verified owner.
- developer_email gmail + no developer_name store Free-webmail dev (kevinsbk@gmail.com), developer_name empty, no business website identity.
- csp_present=false manifest No content_security_policy declared; MV3 default applies but no explicit script constraint.
- js_external_hosts=[editor.phrasely.app] crx Extension contacts external host editor.phrasely.app; not a known bad host but unverifiable data path.
- months_since_update=19 store Last updated Nov 2024; 19 months stale — triggers 6-12 month maintenance band (+3.5) ... wait, 19mo = 12-24mo band.
- verified_publisher=true + is_featured_by_google=true store Verified publisher and featured badges present, partially mitigating reputation; 0c cap applies (monetization/stale checks clean).
Permissions Breakdown
- activeTab medium Grants access to the active tab on user action; low standalone risk.
- content_scripts <all_urls> high Content script injected on ALL URLs gives broad page-read/write capability across every site.
Pillar Scores
Permissions3.50
Reputation6.50
Network2.50
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA
9d7608869398…
Force block
— not fired
Score recovered
no
Elapsed
22.0s