Clear Cache Plus
bgdkbjcdecedfoejdfgeafdodjgfohno
Risk Score
4.71
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and third-party sharing.
- CSP sandbox allows unsafe-eval and unsafe-inline plus remote CDN scripts (cdn.paddle.com, cloudapi.stream).
- browsingData + declarativeNetRequestWithHostAccess are high-capability permissions for a 17-install anonymous developer.
- Developer is free-webmail (gmail) with no developer name and no verifiable business identity.
- Small install count with high-tier permissions flags install_perm_anomaly — elevated tail-attack surface.
Evidence
- Privacy policy is Google's own account policy — scope_extension=false, data_collection=true, third_party_sharing=true api policy URL myaccount.google.com/privacypolicy; 479 KB Google account policy; no extension-specific scope.
- CSP sandbox allows unsafe-eval, unsafe-inline, and remote CDN script sources manifest sandbox CSP includes cdn.paddle.com, buy.paddle.com, cloudapi.stream with unsafe-eval and unsafe-inline.
- External JS hosts include payment and cloud streaming endpoints crx api.paddle.com, paddle.net, cloudapi.stream, cognito-identity. — monetization/cloud infra beyond stated function.
- Developer email is free webmail with no developer name listed store viktornadiezhdin@gmail.com; developer_name empty; no business website verifiable.
- install_perm_anomaly: small_install_high_perm=true (17 installs, browsingData + declarativeNetRequestWithHostAccess) api Only 17 installs but holds two HIGH-tier permissions — elevated tail-attack-surface risk.
- verified_publisher=true but free webmail, no dev name, generic Google policy store Verification badge present but does not resolve identity gaps; v3.5 E cap applies for generic policy.
- No bad_host_hits, no monetization_hits, no affiliate_hits, no CVEs, no code findings api Threat intel and code scan clean; no active exfiltration signals detected.
- months_since_update=11; maintenance moderate risk store Last updated Sept 2025; 11 months puts it in 6-12mo band (+3.5 maintenance).
Permissions Breakdown
- browsingData high Can clear cookies, cache, history — broad destructive and data-access capability.
- declarativeNetRequestWithHostAccess high Allows network request interception/modification with host access scope.
- activeTab medium Access current tab content on user action; scoped but still meaningful.
- alarms low Scheduling only; no data access.
- offscreen low Creates hidden document; low risk without code findings.
- storage low Local extension storage; standard for settings persistence.
Pillar Scores
Permissions4.50
Reputation5.50
Network5.50
Webstore4.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:07
Listing SHA
d0f67567670f…
Force block
— not fired
Score recovered
no
Elapsed
—