Spotify Friend Activity
amlnlcdighbhfciijpnofbpphfnkmeaa
Risk Score
4.39
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: extension uses 'Spotify' brand name without being confirmed owner, gmail dev with no corporate identity.
- Privacy policy fetched but scope_extension==false AND admits data_collection+third_party_sharing — triggers +10.0 per v3.5 rule D.
- Free-webmail developer (gmail.com) with no verified business domain raises accountability concerns.
- Policy hosted on GitHub Pages (free hosting) without extension-specific scope; third-party data sharing admitted.
- Maintenance at 13 months since update crosses 12-24mo band (+6.0).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; brands_mentioned=['spotify'], dev domain=gmail.com.
- privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
- free_webmail_dev store Developer email jack.weatherford@gmail.com; no verified business domain; domain_age_ct not queried (free webmail).
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP declared.
- maintenance_stale store months_since_update=13; falls in 12-24mo band (+6.0 maintenance pillar).
- external_hosts crx js_external_hosts: chrome.google.com, github.com, guc-spclient.spotify.com, i.imgur.com, open.spotify.com (5 hosts, 3 countries).
- no_bad_hosts_no_cve api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], cve_findings_raw=[], code_findings_raw=[] — clean scan.
- operator_cluster_clean api operator_cluster.sibling_count=0; no related extensions under same fingerprint.
Permissions Breakdown
- storage low Persists extension state/settings; no cross-site read capability.
- host_permission: https://open.spotify.com/* medium Scoped to single domain; enables content script injection and request access to Spotify web player only.
Pillar Scores
Permissions1.30
Reputation7.50
Network2.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
2f1fe357a27c…
Force block
— not fired
Score recovered
no
Elapsed
20.8s