Apollo.io: Free B2B Phone Number & Email Finder
alhgpfoeiimagjlnfekdhkjlkiomcapa
Risk Score
4.04
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched and scoped to company not extension; admits data collection and third-party sharing without extension-specific scope — scores max privacy risk.
- Broad *://*/* host permission with scripting enables script injection on every website user visits.
- 6 innerHTML DOM-XSS sinks across background, panel, and vendor bundles; CSP present but connect-src is broad.
- No developer name listed in store despite verified publisher status; developer_name field empty.
- tabs + webNavigation + broad host = full browsing history observable by extension on all pages.
Evidence
- broad_host_permission manifest *://*/* host permission grants access to every website; combined with scripting and tabs raises capability risk.
- privacy_policy_no_extension_scope api Policy fetched (163k chars); scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
- dom_xss_sinks crx 6 innerHTML-from-variable findings across background, panel, vendor, and LinkedIn iframe bundles.
- verified_publisher_featured store Verified publisher + featured by Google; applied discounts capped per 0c (no stale/CVE/domain issues here).
- csp_broad_connect_src manifest connect-src lists 18+ endpoints including Twilio, Amplitude, NewRelic, Pusher, customer.io, Sentry.
- no_bad_hosts_no_affiliate api threat_intel shows no bad_host_hits, no affiliate_hits, no monetization_hits; developer domain resolves.
- recently_updated store Last updated June 8 2026; months_since_update=0; maintenance risk is minimal.
- no_cve_findings crx cve_findings_raw is empty; no known-vulnerable bundled libraries detected.
Permissions Breakdown
- contextMenus low Adds right-click menu items; limited risk.
- notifications low Can show desktop notifications; minor user-annoyance risk.
- scripting medium Can inject scripts into pages; elevated when paired with broad host access.
- storage low Local/sync storage; no direct exfil path.
- tabs medium Can read tab URLs and titles across all tabs.
- webNavigation medium Can observe full navigation events across all pages.
- sidePanel low Displays sidebar UI; no direct data-access risk.
- *://*/* high Broad host permission; allows script injection and data access on every site.
Pillar Scores
Permissions5.80
Reputation2.00
Network3.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
57bf9acf924b…
Force block
— not fired
Score recovered
no
Elapsed
39.1s