VB Notes - YouTube Notes Pro
begjfebldmhfcbgohdgcpajedndfdnej
Risk Score
4.75
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL times out (ConnectTimeout) — effectively no accessible policy; scored as fetched==false.
- YouTube brand impersonation in title by unverified gmail developer; confirmed_owner==false.
- innerHTML DOM-XSS sink in content.js with no CSP present; amplifies XSS risk on YouTube/Vimeo.
- Description promises recording capability but lacks tabCapture/desktopCapture — permission mismatch.
- External JS host quilljs.com loaded without CSP; MV3 but no content_security_policy set.
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (ConnectTimeout); treated as no accessible policy → +10.0 privacy.
- brand_impersonation_youtube store brand_mention.is_impersonation==true, confirmed_owner==false, developer on gmail.com → +2.0 reputation.
- free_webmail_developer store Developer email cipherux@gmail.com; not verified publisher, no business domain → +1.5 reputation.
- dom_xss_sink_no_csp crx dom_sink_innerhtml_userctrl in content.js + csp_present==false → +2.0 code quality (FIX B).
- description_promise_mismatch store Promises recording but lacks tabCapture/desktopCapture → +2.0 webstore.
- external_js_host_quilljs crx js_external_hosts includes quilljs.com; no CSP to restrict script loading.
- maintenance_6_to_12_months store months_since_update==9 → maintenance +3.5.
- no_cve_findings crx cve_findings_raw empty → CVE pillar 0.0.
Permissions Breakdown
- identity low OAuth token access; scoped to extension sign-in, low risk without broad host.
- storage low Local data persistence only; standard low-risk permission.
- activeTab low Transient access to current tab on user gesture; well-scoped.
- tabs medium Can read tab URLs and titles across all tabs; moderate metadata exposure.
- downloads medium Can trigger file downloads; potential for unwanted file writes.
- https://www.youtube.com/* medium Content script and host access on YouTube; scoped to stated function.
- https://vimeo.com/* medium Content script and host access on Vimeo; scoped to stated function.
- https://vbnotes.com/* low Access to own backend domain only; expected for notes sync.
Pillar Scores
Permissions2.30
Reputation6.50
Network2.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-08 13:48
Listing SHA
47e50bf9900d…
Force block
— not fired
Score recovered
no
Elapsed
—