Symvek Shield: Privacy Score & Tracker Blocker
apgiipaoknpflkngmeibegmbijppmpog
Risk Score
3.87
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- No developer name listed and no verified publisher badge; low accountability for a privacy-tool claiming broad host access.
- webRequest + <all_urls> + content_scripts on all URLs gives full browsing observation capability to unknown developer.
- Privacy policy URL points to Chrome Web Store listing page, not a real policy; classified as scoped but lacks retention disclosure.
- Only 5 installs with HIGH-tier permissions flagged by install_perm_anomaly — small-install/high-perm tail-attack-surface signal.
- MV3 + no CSP: no CSP penalty applies (MV3 default), but api.symvek.com outbound contact is unverifiable without code findings.
Evidence
- high_perm_broad_host manifest webRequest + <all_urls> + content_scripts on all URLs; justified-broad discount applied for PrivacyTool category.
- no_developer_name store developer_name is empty string; no 'Offered by' identity visible; +1.0 reputation penalty.
- privacy_policy_is_store_page store privacy_policy_url resolves to the CWS listing itself, not a standalone policy; retention==false.
- small_install_high_perm api install_perm_anomaly.small_install_high_perm==true; 5 installs with HIGH-tier permissions.
- outbound_host crx js_external_hosts: [api.symvek.com]; single dev-controlled domain, no bad-host hits.
- third_party_sharing_admitted api privacy_policy_classification.third_party_sharing==true; retention==false; privacy pillar elevated.
- no_verified_publisher store verified_publisher==false, is_featured_by_google==false; no trust discounts applicable.
- cve_clean crx cve_findings_raw empty; code_findings_raw empty; obfuscation_score 0.0.
Permissions Breakdown
- storage low Standard local storage for settings/state.
- tabs medium Can read tab URLs and metadata across all open tabs.
- declarativeNetRequest medium Core function for tracker blocking; appropriate for category.
- declarativeNetRequestFeedback medium Allows reading which rules fired; minor data-exposure risk.
- webRequest high Can observe all HTTP requests on <all_urls>; broad surveillance capability.
- webNavigation medium Tracks navigation events; combined with tabs increases browsing visibility.
- <all_urls> (host_permission) high Content scripts inject into every site; pairs with webRequest for full browsing scope.
Pillar Scores
Permissions5.50
Reputation6.00
Network4.00
Webstore2.50
Maintenance0.00
Privacy6.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA
6f8c2920820a…
Force block
— not fired
Score recovered
no
Elapsed
24.5s