Zoom Page WE
bcdjhkphgmiapajkphennjfgoehpodpk
Risk Score
6.03
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- 38 months since last update — extension is effectively abandoned with broad content-script access on all URLs.
- Privacy policy is Google's generic account policy; not scoped to this extension, admits data collection and 3rd-party sharing.
- Brand impersonation: name contains 'Zoom' but developer is unaffiliated (gmx.com free-webmail dev, not verified).
- Content scripts injected into all http/https/file pages with no CSP — full DOM read/write on every site visited.
- Developer email on gmx.com (free webmail, looks_throwaway flagged); no verified publisher badge.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; 'Zoom' mentioned but confirmed_owner=false, dev is dw-dev@gmx.com.
- privacy_policy_generic store Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5-D).
- stale_extension store Last updated April 2023; months_since_update=38. Triggers +10.0 Maintenance and triple-stale fingerprint.
- content_scripts_broad manifest content_scripts_matches covers http://*/*, https://*/*, file:///*, no CSP present.
- throwaway_dev_domain api developer_domain_info.looks_throwaway=true for gmx.com; free webmail domain.
- featured_by_google store is_featured_by_google=true; provides -2.0 Reputation discount (not verified publisher).
- no_cve_no_bad_hosts crx cve_findings_raw=[], bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no active threat signals.
- triple_stale_fingerprint store months>24 + MV3 (no CVEs present, so partial) + no CSP; v2c +2.0 Webstore applied.
Permissions Breakdown
- tabs medium Can read tab URLs and titles; moderate data exposure.
- webNavigation medium Observes navigation events across all tabs; page-visit tracking risk.
- contextMenus low Adds items to right-click menus; low standalone risk.
- notifications low Can show browser notifications; low risk.
- storage low Local extension storage; low risk.
- content_scripts http://*/* high Injects scripts into all HTTP pages; broad read/write access to page content.
- content_scripts https://*/* high Injects scripts into all HTTPS pages; broad read/write access to page content.
- content_scripts file:///* medium Injects scripts into local files; can read local filesystem content.
Pillar Scores
Permissions4.50
Reputation7.50
Network0.00
Webstore4.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA
74033caefba3…
Force block
— not fired
Score recovered
no
Elapsed
23.2s