PDF Forge
aihkhafnbpomjadbkobpnojmojgcilah
Risk Score
5.01
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — worst-case privacy disclosure.
- Free-webmail dev (gmail) with no verified business identity; unverified domain aimythe.com.
- scripting + <all_urls> content script injected on every page gives full page-content read capability across all sites.
- Only 5 installs with HIGH-tier permissions: tail-attack-surface risk if repurposed post-install.
- 9 external JS hosts referenced with no CSP; MV3 but no content_security_policy set.
Evidence
- privacy_policy_admits_collection_sharing_not_scoped api Fetched policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
- free_webmail_developer store Developer email pabyngono@gmail.com; no verified publisher badge; free-webmail dev with no confirmed business.
- broad_host_scripting manifest scripting + <all_urls> host_permissions + content_scripts on <all_urls>; full page access on every site.
- no_csp manifest content_security_policy is null; csp_present=false; 9 external JS hosts referenced in extension.
- small_install_high_perm_anomaly api install_perm_anomaly.small_install_high_perm=true; 5 installs with HIGH-tier permissions.
- 9_external_js_hosts crx js_external_hosts includes github.com, hertzen.com, fpdf.org, yworks.com and 5 others; >3 distinct domains.
- no_operator_siblings api operator_cluster.sibling_count=0; no sibling extensions detected.
- cve_findings_empty api cve_findings_raw=[]; no known CVEs detected in bundled libraries.
Permissions Breakdown
- activeTab low Scoped to user-initiated tab interaction only.
- downloads medium Can write files to user's disk; reasonable for PDF export.
- storage low Local extension storage only.
- scripting high Programmatic script injection into pages; amplified by <all_urls> host access.
- <all_urls> (host_permissions) high Grants access to every site the user visits; enables content capture on sensitive pages.
- <all_urls> (content_scripts_matches) high Content script auto-injected on every page load; broad passive reach.
Pillar Scores
Permissions6.50
Reputation7.50
Network3.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 08:01
Listing SHA
deaed53c8769…
Force block
— not fired
Score recovered
no
Elapsed
—