Ground News - Bias Checker
agleiimpggapjekcdhdjbmegjbbkleie
Risk Score
3.27
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Content scripts run on virtually all HTTP/HTTPS pages — broad read access to page content across the web.
- Uninstall URL hijack flag set; extension registers an uninstall URL pointing to a third party.
- No CSP defined (MV3 default applies but no explicit policy); jquery 3.6.1 bundled without CSP amplifies risk slightly.
- Months since update is 17 — borderline stale; verified-publisher discount capped per invariant 0c.
- Developer name field empty despite verified-publisher status; minor accountability gap.
Evidence
- content_scripts_broad_host manifest content_scripts match http://*/* and https://*/* — effectively all web pages.
- uninstall_url_hijack crx uninstall_url_hijack=true; target null in data but flag set — registers chrome.runtime.setUninstallURL.
- verified_publisher_featured store Verified publisher + Google Featured badge; reputation discount capped at -1.0 (months_since_update=17 >18 threshold approaching, but 17 not >18).
- privacy_policy_adequate api Policy scoped to extension, discloses data collection, retention, and third-party sharing.
- jquery_3_6_1_no_csp crx jquery@3.6.1 bundled; no explicit CSP; no CVEs found in cve_findings_raw.
- maintenance_stale store 17 months since last update; scores at 6-12 month band (+3.5) — borderline stale.
- no_bad_hosts_no_monetization api threat_intel shows no bad_host_hits, monetization_hits, or affiliate_hits.
- code_clean crx code_findings_raw empty; obfuscation_score=0.0; 12 JS files scanned cleanly.
Permissions Breakdown
- tabs medium Can read tab URLs and titles; moderate risk for a content-analysis extension.
- storage low Local/sync storage only; standard for preferences.
- host: https://extension.ground.news/* low Scoped to developer-owned API endpoint.
- host: https://production.checkitt.news/api/* low Scoped to developer-operated API; secondary domain still dev-controlled.
- content_scripts: http://*/* and https://*/* high Effectively broad host access via content scripts on all HTTP/HTTPS pages.
Pillar Scores
Permissions4.50
Reputation2.00
Network2.00
Webstore3.50
Maintenance6.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:18
Listing SHA
7759f9719ca3…
Force block
— not fired
Score recovered
no
Elapsed
—