Picture-in-Picture YouTube - Netflix and more
ahdijafdcpkcefendeaobodkfjcmphac
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic Google Sites policy).
- Brand impersonation: extension names YouTube and Netflix without verified ownership.
- Developer is free-webmail only (gmail) with no business domain; unverifiable identity.
- Extension last updated 35 months ago — approaching zombie status with 20K installs.
- No CSP on MV3 extension; v2 calibration adds +2.0 to network pillar for MV2+no-CSP, but MV3 exempted — still no declared CSP.
Evidence
- brand_impersonation store brands_mentioned=[youtube,netflix], confirmed_owner=false, is_impersonation=true.
- free_webmail_developer store developer_email=barreiro01919@gmail.com; no business domain; identity unverifiable.
- privacy_policy_generic_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.0.
- maintenance_stale store months_since_update=35; in 24-36mo band → +8.5.
- no_bad_hosts_or_affiliates api threat_intel bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no malicious network signals.
- no_code_findings crx code_findings_raw=[], obfuscation_score=0.0; code quality pillar 0.0.
- featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount (Featured badge).
- install_count_20k store 20,000 installs; >10K webstore signal +1.0.
Permissions Breakdown
- activeTab low Grants access to current tab only on user gesture; low blast radius.
- scripting medium Allows programmatic script injection into pages; medium risk without broad host perms.
Pillar Scores
Permissions1.30
Reputation7.50
Network2.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA
e41343000801…
Force block
— not fired
Score recovered
no
Elapsed
20.5s