PerfectPost: makes Linkedin 10x better
bagapgnffhmfccajdbbjcgalkphdjccn
Risk Score
4.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- No CSP + 4x innerHTML DOM-XSS sinks on linkedin.com elevates DOM-XSS risk to content-script context.
- Developer domain perfectpost.fr does not resolve; verified-publisher discount capped per invariant 0c.
- Brand impersonation flag: LinkedIn brand mentioned, developer not confirmed owner, not a verified LinkedIn partner.
- webRequest permission on linkedin.com enables observation of all LinkedIn network traffic including auth tokens.
Evidence
- privacy_policy_generic_google store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 rule D).
- no_csp_plus_innerhtml_sinks crx csp_present=false AND 4 dom_sink_innerhtml_userctrl findings → FIX B applies: each counts as +2.0 code quality (capped at 10).
- developer_domain_not_resolving api perfectpost.fr resolves=false; verified-publisher discount capped at -1.0 per invariant 0c.
- brand_impersonation store brand_mention.is_impersonation=true for LinkedIn; verified_publisher=true so +1.0 Reputation (v3.2 rule 9).
- uninstall_url_hijack crx uninstall_url_hijack=true; +3.0 Webstore per rubric.
- js_external_hosts_count crx 12 distinct external hosts including api.mixpanel.com (telemetry), github.com, gsap.com, mui.com → >3 distinct domains +1.5 Network.
- react_v16_13_1_bundled crx React 16.13.1 bundled; no CVE hits in cve_findings_raw so no CVE score added.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discount capped at -1.0 due to non-resolving dev domain.
Permissions Breakdown
- alarms low Scheduling only; minimal abuse surface.
- storage low Local data persistence; standard for productivity tools.
- tabs medium Can read tab URLs and titles across browsing session.
- webRequest high Can observe all network requests on in-scope hosts; elevated risk.
- *://*.linkedin.com/* medium Scoped to LinkedIn only; matches stated function but accesses sensitive professional data.
Pillar Scores
Permissions4.50
Reputation4.00
Network4.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA
28b9a0c4af5b…
Force block
— not fired
Score recovered
no
Elapsed
29.5s