YouTube To Transcript: AI Summarizer & Chat
bcmoplgjpddohaelhnnodojbamdobbhc
Risk Score
3.34
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Gmail developer with no verified publisher status; unverifiable identity accountability.
- Brand impersonation: uses 'YouTube' in name/title but dev is not confirmed YouTube/Google owner.
- install_url_hijack: onInstalled opens a third-party URL (potential redirect/phishing on install).
- AI extension processes YouTube page content and sends to developer backend (youtubetotranscript.com).
- DOM-XSS sink (innerHTML) in popup.js with no CSP set; risk amplified by FIX B.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; developer is gmail.com, not Google/YouTube; +2.0 Reputation.
- install_url_hijack manifest install_url_hijack=true; onInstalled opens 3rd-party URL; +2.0 Webstore.
- free_webmail_dev store Developer email andrej.simunaj@gmail.com; no verified publisher, no org; +1.5 Reputation.
- ai_page_content_processing store AI extension fetching YouTube transcripts and sending to developer backend; +2.5 Webstore.
- dom_sink_innerhtml_no_csp crx innerHTML in popup.js + csp_present=false triggers FIX B: +2.0 Code Quality.
- privacy_policy_adequate api Policy fetched, scoped to extension, data_collection+retention+3rd_party all disclosed; +1.0 Privacy.
- maintenance_3_6mo store months_since_update=4; in 3-6mo band; +1.5 Maintenance.
- no_cve_findings crx cve_findings_raw empty; CVE pillar=0.0.
Permissions Breakdown
- storage low Stores local extension data; low risk.
- activeTab low Access only to currently active tab on user interaction.
- tabs medium Can read tab URLs and titles; moderate privacy exposure.
- notifications low Shows desktop notifications; minimal risk.
- alarms low Schedules background tasks; low risk.
- identity low OAuth identity without declared scopes; low risk in isolation.
- https://www.youtube.com/* medium Host permission scoped to YouTube only; matches stated function.
- https://youtubetotranscript.com/* low Dev-owned backend domain; expected for AI feature calls.
Pillar Scores
Permissions2.60
Reputation6.50
Network2.00
Webstore4.50
Maintenance1.50
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-17 05:11
Listing SHA
c829fec80220…
Force block
— not fired
Score recovered
no
Elapsed
—