Private DNS
agmphbjkmidhennimplkfekmikacfhll
Risk Score
3.17
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Developer uses Gmail with no verified business identity and no developer name listed.
- Host permissions point to a raw IP and dynamic DNS (duckdns.org) over HTTP — unencrypted traffic to unknown infrastructure.
- Privacy policy admits data collection and third-party sharing but lacks retention disclosure; hosted on dynamic DNS.
- No CSP present (MV3 mitigates but innerHTML sink in popup.js is still a DOM-XSS risk).
- Small install base (1 000) with network reach to developer-controlled servers raises future-sale/compromise concern.
Evidence
- developer_identity store Developer email is Gmail; no developer name set; no verified business domain.
- host_permissions_raw_ip manifest http://129.154.249.32:9053/* — raw IPv4 host permission, no TLS, unknown infrastructure.
- host_permissions_dynamic_dns manifest HTTP and HTTPS host perms to yogvidwankhede.duckdns.org — dynamic DNS, no stable domain ownership.
- privacy_policy_weaknesses api Policy fetched, scoped, but admits data_collection+third_party_sharing with no retention clause.
- dom_xss_sink crx popup.js: innerHTML written from variable; no CSP to mitigate injection.
- no_csp manifest content_security_policy is null; MV3 provides some default protection but XSS sink remains.
- verified_publisher store verified_publisher == true; reduces reputation risk but capped by Gmail dev email.
- maintenance store Last updated October 2025; 8 months since update — in 3-6 month band (+1.5).
Permissions Breakdown
- storage low Stores extension settings locally; minimal risk.
- host: http://129.154.249.32:9053/* medium Raw IP endpoint; extension sends DNS/network requests to a developer-controlled server.
- host: https://yogvidwankhede.duckdns.org/* medium DuckDNS subdomain (dynamic DNS); developer-controlled but not a stable domain.
- host: http://yogvidwankhede.duckdns.org/* medium HTTP (unencrypted) host permission to dynamic DNS subdomain; intercept risk.
Pillar Scores
Permissions2.00
Reputation6.50
Network3.00
Webstore1.50
Maintenance1.50
Privacy3.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA
4a0fc566faea…
Force block
— not fired
Score recovered
no
Elapsed
22.8s