Open in Microsoft Edge
akkeflfepdogekcemgkidllneichjhce
Risk Score
7.34
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- nativeMessaging with unrecognized publisher — arbitrary code execution on host OS possible.
- Microsoft brand impersonation by gmail.com developer with no verified ownership.
- Extension not updated in 45 months — abandoned, acquisition risk.
- Privacy policy is Google's generic account policy — does not scope to this extension; data collection and 3rd-party sharing admitted.
- install_url_hijack and uninstall_url_hijack both true — redirects user on install/uninstall.
Evidence
- nativeMessaging_unrecognized_publisher crx has_native_messaging=true, publisher_recognized=false — +3.0 permissions.
- brand_impersonation_microsoft store brand_mention.is_impersonation=true, confirmed_owner=false, developer on gmail.com.
- install_and_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true — webstore +2.0+3.0.
- abandoned_extension store last_updated September 2022, months_since_update=45 — maintenance score 10.0.
- generic_google_privacy_policy api Policy is myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- no_csp crx content_security_policy=null; MV3 strict default applies — no extra network penalty.
- free_webmail_developer store Developer email thomas.davis.19791210@gmail.com — numbered alias pattern on free webmail.
- dom_sink_innerhtml crx dom_sink_innerhtml_userctrl in js/common.js; no CSP present — elevated XSS risk.
Permissions Breakdown
- storage low Stores local extension preferences; low risk in isolation.
- contextMenus low Adds right-click menu items; limited capability.
- nativeMessaging high Communicates with native host app; publisher not recognized — full OS-level escape risk.
Pillar Scores
Permissions7.00
Reputation8.50
Network2.00
Webstore7.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| <fsssiedx{$'sssiedx | 7.28 | High | block | 2026-08-17 |
| %22fsssiedxf$"sssiedx | 7.68 | High | block | 2026-08-17 |
| 'fsssiedxf$"sssiedx | 7.32 | High | block | 2026-08-17 |
| <fsssiedxf$'sssiedx | 7.38 | High | block | 2026-08-17 |
| <fsssiedx{$"sssiedx | 7.05 | High | block | 2026-08-17 |
| <fsssiedxi"sssiedx | 7.25 | High | review | 2026-08-17 |
| <fsssiedxa sssiedx | 7.27 | High | block | 2026-08-17 |
| fsssiedx<sssiedx | 7.47 | High | block | 2026-08-17 |
| <fsssiedxa$"sssiedx | 7.09 | High | block | 2026-08-13 |
| <fsssiedxa$'sssiedx | 6.25 | High | block | 2026-08-13 |
| <fsssiedxa xx psssiedx | 7.25 | High | block | 2026-08-13 |
| fsssiedxa<sssiedx | 7.28 | High | block | 2026-08-13 |
| fsssiedxa xx psssiedx | 7.44 | High | block | 2026-08-07 |
| sssieddrubricxsx | 7.26 | High | block | 2026-08-07 |
| v3.6"><script>Ggbz(9463)</script> | 7.33 | High | block | 2026-08-05 |
| dfb[[${98991*97996}]]xca | 7.28 | High | block | 2026-08-05 |
| bfgx7271%C0%BEz1%C0%BCz2a%90bcxhjl7271 | 7.15 | High | block | 2026-08-05 |
| v3.6&n907032=v966551 | 6.39 | High | block | 2026-08-05 |
| %76%33%2E%36%39%38%37%38%22%28%29%3B%7D%5D%39%37%31%36 | 7.35 | High | block | 2026-08-04 |
| v3.6&n936425=v933863 | 7.27 | High | block | 2026-08-04 |
| %76%33%2E%36%39%32%39%35%22%28%29%3B%7D%5D%39%31%31%35 | 7.09 | High | block | 2026-07-29 |
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%64%6B%61%57%28%39%39%30%37%34%29%22 | 7.22 | High | block | 2026-07-29 |
| dfb__${98991*97996}__::.x | 6.30 | High | block | 2026-07-29 |
| bfgx6060%C0%BEz1%C0%BCz2a%90bcxhjl6060 | 7.05 | High | block | 2026-07-29 |
| dfb{{98991*97996}}xca | 7.49 | High | review | 2026-07-29 |
| bfg10322<s1﹥s2ʺs3ʹhjl10322 | 7.15 | High | block | 2026-07-29 |
| v3.6&n943949=v907024 | 7.34 | High | block | 2026-07-29 |
| v3.6 | 7.34 | High | block | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
9a905546b1f0…
Force block
— not fired
Score recovered
no
Elapsed
20.1s