SignalHire - find email or phone number
aeidadjdhppdffggfgjpanbafaedankd
Risk Score
4.89
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies + scripting + <all_urls>: can intercept sessions and inject code on every site including LinkedIn profiles scraped at scale.
- Privacy policy fetch failed (HTTP error); policy content unverifiable — treated as no effective policy.
- No developer name in store listing reduces accountability; email domain resolves but no verified publisher badge.
- Uninstall URL hijack flag set — extension registers a third-party URL on uninstall, a known monetization/tracking pattern.
- MV3 without CSP declared; scripting+<all_urls> combo gives broad runtime injection capability across all visited pages.
Evidence
- cookies+scripting+<all_urls> manifest Triple HIGH-risk combo: cookies, scripting, and <all_urls> enables full session+page interception on any site.
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false due to HTTPError; policy content cannot be assessed — scored as +10.0.
- uninstall_url_hijack crx uninstall_url_hijack==true; extension registers a callback URL on uninstall, a known monetization/tracking signal.
- no_developer_name store developer_name is empty string; verified_publisher==false; is_featured_by_google==true applied as -2.0 rep discount.
- content_scripts_narrow_vs_all_urls manifest content_scripts scoped to linkedin.com+signalhire.com but host_permissions=<all_urls>; scope mismatch +1.0 perm.
- js_external_hosts_dev_tools crx js_external_hosts includes github.com, npms.io, react.dev, wxt.dev — appear to be dev-tool references, not live exfil.
- install_count_300k store 300,000 installs with is_featured_by_google; high blast radius if compromised.
- no_bad_hosts_no_cves api threat_intel.bad_host_hits empty, cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty.
Permissions Breakdown
- storage low Local data persistence; low standalone risk.
- cookies high Can read/write cookies across all origins given <all_urls> host permission.
- tabs medium Exposes URL and title of all open tabs; moderate privacy surface.
- scripting high Allows arbitrary JS injection into any page via <all_urls>.
- notifications low UI notifications only; no data-exfil risk on its own.
- <all_urls> high Broad host access; combined with cookies+scripting enables full page+session interception.
Pillar Scores
Permissions7.00
Reputation4.00
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-10 05:41
Listing SHA
6c1281dc688a…
Force block
— not fired
Score recovered
no
Elapsed
—