Adblock for Youtube - skip ads
annjejmdobkjaneeafkbpipgohafpcom
Risk Score
4.05
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: uses 'youtube' in name/title without being affiliated with YouTube/Google.
- Free-webmail developer (gmail) with no verifiable business identity behind the extension.
- Broad *://*/* host + content_scripts on all pages; full page-read capability on every site visited.
- Privacy policy present but no data-retention disclosure and third-party sharing not mentioned.
- Verified-publisher badge present but developer identity is anonymous gmail account.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; 'youtube' listed in brands_mentioned; confirmed_owner=false.
- free_webmail_developer manifest developer_email=bankgokteen@gmail.com; developer_name empty; no business domain.
- broad_host_permissions manifest host_permissions=[*://*/*] and content_scripts_matches=[*://*/*]; all-sites reach.
- verified_publisher store verified_publisher=true and is_featured_by_google=true; reputation discounts apply but capped.
- privacy_policy_gaps api retention=false, third_party_silence=true; scope_extension=true, data_collection=true.
- no_csp manifest content_security_policy=null; MV3 strict default applies, no v2 penalty triggered.
- no_code_findings crx code_findings_raw=[]; obfuscation_score=0.0; no exfil or eval signals detected.
- no_threat_intel_hits api bad_host_hits=[], monetization_hits=[], affiliate_hits=[]; no external JS hosts.
Permissions Breakdown
- tabs medium Can read tab URLs and titles; moderate risk for an adblock extension.
- declarativeNetRequest medium Blocks/redirects network requests; expected for adblockers, medium residual risk.
- storage low Local settings storage only; low risk.
- host_permissions: *://*/* high Broad host access across all sites; combined with content_scripts it can read/modify any page.
- content_scripts: *://*/* high Content scripts injected on every page; broad reach even if no exfil detected today.
Pillar Scores
Permissions5.50
Reputation7.50
Network0.00
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA
e3c36e3deaf3…
Force block
— not fired
Score recovered
no
Elapsed
23.0s