Auto-join for Google Meet
ajfokipknlmjhcioemgnofkpmdnbaldi
Risk Score
4.66
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Developer uses free Gmail address with no verified identity; no dev name listed.
- Privacy policy is only 83 chars, unscoped to this extension — effectively a stub.
- Extension last updated 27 months ago; stale for enterprise deployment.
- Brand impersonation: mentions Google/Zoom but developer is unaffiliated gmail user.
- Content scripts on Zoom Gov (zoomgov.com) — sensitive domain for unverified dev.
Evidence
- free_webmail_dev store Developer email zoomcorderhelp@gmail.com; no verified org, no developer name.
- privacy_policy_stub api Policy fetched but only 83 chars, scope_extension=false, data_collection=false — effectively empty.
- stale_extension store Last updated May 2024; 27 months since update — high abandonment risk.
- brand_impersonation store brand_mention.is_impersonation=true for Google; developer not confirmed owner.
- content_scripts_sensitive_domains manifest Content scripts injected into zoomgov.com — government video conferencing domain.
- no_code_findings crx code_findings_raw empty, obfuscation_score 0.0, no external hosts — clean scan.
- no_cve_findings crx jquery 3.6.0 bundled; cve_findings_raw empty — no known CVEs flagged.
- no_operator_cluster api sibling_count=0; no related suspicious extensions under same fingerprint.
Permissions Breakdown
- content_scripts: *://*.gotomeeting.com/* medium Injects JS into GoToMeeting pages; limited to declared domain.
- content_scripts: *://*.gotowebinar.com/* medium Injects JS into GoToWebinar pages; limited to declared domain.
- content_scripts: *://*.meet.google.com/* medium Injects JS into Google Meet; matches stated function.
- content_scripts: *://*.zoom.us/* medium Injects JS into Zoom; limited to declared domain.
- content_scripts: *://*.zoomgov.com/* medium Injects JS into Zoom Gov; sensitive domain, limited to declared.
Pillar Scores
Permissions1.50
Reputation7.50
Network0.00
Webstore2.50
Maintenance8.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:59
Listing SHA
5d8405b05a24…
Force block
— not fired
Score recovered
no
Elapsed
—