TuneEase
bhdjjppbnlpjpeicimhemencfgjeldoa
Risk Score
4.31
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: Spotify brand mentioned, developer not confirmed owner, free-webmail identity only.
- Install URL hijack: onInstalled opens /setting.html; uninstall URL hijack also flagged.
- Privacy policy fetched but scope_extension==false and data_collection==false; policy not scoped to this extension.
- Free-webmail developer (gmail.com) with no verified business domain raises accountability gap.
- Contacts 7 external hosts including vercel.app backend and twitter.com with no CSP (MV3 mitigates but network surface broad).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, Spotify mentioned, confirmed_owner=false, developer domain is gmail.com.
- install_url_hijack crx install_url_hijack=true targeting /setting.html; uninstall_url_hijack=true.
- free_webmail_developer store Developer email dzungnguyen179@gmail.com; no verified publisher badge.
- privacy_policy_not_scoped api Policy fetched but scope_extension=false, data_collection=false; generic policy not scoped to extension.
- external_hosts_breadth crx 7 external hosts: accounts.spotify.com, api.spotify.com, open.spotify.com, spotify-notification-api.vercel.app, twitter.com, www.tunease.com, localhost.
- no_csp manifest content_security_policy=null; MV3 provides defaults but no explicit CSP strengthening.
- cve_findings crx cve_findings_raw empty; no known CVEs detected.
- operator_cluster api sibling_count=0; no sibling extensions under same fingerprint.
Permissions Breakdown
- contextMenus low Adds right-click menu items; minimal data access.
- declarativeContent low Page state inspection for UI triggers; no data exfiltration.
- storage low Local key-value storage only; standard extension use.
- host: http://localhost/* low Localhost dev/API access; limited real-world exposure.
- host: https://www.tunease.com/* low Scoped to dev-owned domain; matches stated function.
Pillar Scores
Permissions0.90
Reputation7.50
Network1.50
Webstore7.50
Maintenance1.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA
e9df57232965…
Force block
— not fired
Score recovered
no
Elapsed
20.3s