Webshare Proxy Extension
bdokeillmfmaogjpficejjcjekcflkdh
Risk Score
4.67
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- proxy+webRequest+<all_urls>+cookies: full traffic interception and credential theft capability on compromise.
- Privacy policy fetched but scope_extension=false and admits data collection + third-party sharing — worst-case privacy posture.
- No CSP on MV3 extension with innerHTML DOM-XSS sink in popup JS.
- No developer name listed; webshare.io domain resolves and is not throwaway but identity accountability is reduced.
- posthog-js analytics bundled — user behaviour telemetry without extension-scoped retention disclosure.
Evidence
- high_permission_combo manifest proxy+webRequest+cookies+privacy+<all_urls> — maximum traffic interception surface for a proxy tool.
- privacy_policy_generic crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true, retention=false → +10.0 privacy.
- no_csp manifest content_security_policy is null on MV3 extension with innerHTML sink in popup.
- dom_xss_sink crx dom_sink_innerhtml_userctrl in popup-DBWXjTrF.js; no CSP present → elevated to +2.0 code quality.
- featured_by_google store is_featured_by_google=true — partial trust signal, but not verified publisher.
- no_developer_name store developer_name is empty string; email domain webshare.io resolves and is not throwaway.
- posthog_analytics crx posthog-js detected in sourcemaps; analytics telemetry without extension-scoped retention disclosure.
- no_bad_hosts api threat_intel bad_host_hits, monetization_hits, affiliate_hits all empty; developer domain resolves.
Permissions Breakdown
- proxy high Can redirect all browser traffic through attacker-controlled servers if compromised.
- webRequest high Intercept and inspect all HTTP requests across all URLs.
- privacy high Can alter Chrome privacy settings including proxy, tracking protection, etc.
- cookies high Access to cookies on all URLs combined with <all_urls> host access is critical.
- <all_urls> high Full host access to every site the user visits.
- identity low OAuth identity access; low risk without explicit scopes.
- storage low Local extension storage; low standalone risk.
- webRequestAuthProvider high Can inject proxy credentials into auth challenges — needed for proxy auth but sensitive.
Pillar Scores
Permissions7.00
Reputation4.50
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA
b6f4484a058d…
Force block
— not fired
Score recovered
no
Elapsed
26.0s