X (Twitter) Mass Unfollow
bidolfkgmbnlnijabkjafdajjpocfhol
Risk Score
5.27
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy (scope_extension=false, admits data collection and third-party sharing) — scores maximum privacy risk.
- Brand impersonation: 'twitter' mentioned in name/description by unverified gmail developer who does not own the brand.
- Developer uses free webmail (gmail) with no business domain or verified publisher status.
- Install URL hijack opens options.html on install — minor UX manipulation but flags low-quality governance.
- Extension last updated 13 months ago with no changelog; moderate staleness for a social-platform automation tool.
Evidence
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case privacy score.
- brand_impersonation store brand_mention.is_impersonation=true for 'twitter'; developer is unverified gmail user, not Twitter/X Corp.
- free_webmail_developer store Developer email olushilukmon03@gmail.com; no business domain, no verified publisher badge.
- install_url_hijack manifest install_url_hijack=true targeting options.html on install — low-severity governance flag.
- content_script_scope manifest content_scripts_matches restricted to https://*.x.com/*/following — narrow, fits stated purpose.
- maintenance_staleness store Last updated May 2025, months_since_update=13; falls in 12-24mo bracket (+6.0 maintenance).
- no_csp manifest content_security_policy=null; MV3 default applies, no amplifier triggered (no CVEs, no high-risk code findings).
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, no external JS hosts beyond github.com.
Permissions Breakdown
- storage low Stores user preferences locally; minimal risk.
- declarativeContent low Controls when extension activates; no data access.
- scripting medium Can inject scripts into active tab; scoped to x.com/following via content_scripts.
- activeTab low Access only to user-activated tab; limited scope.
Pillar Scores
Permissions2.30
Reputation7.50
Network0.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA
e37233b1985c…
Force block
— not fired
Score recovered
no
Elapsed
22.5s