Trocker
bjojfeillmmoeadgobbcknkgdkngbcdb
Risk Score
4.52
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope data handling to this extension at all.
- Developer is a free-webmail identity (gmail.com) with no verified developer name or business domain.
- declarativeNetRequestWithHostAccess + <all_urls> gives broad network interception capability across all sites.
- No CSP defined (MV3 default applies but no explicit policy); innerHTML DOM-XSS sink in options.js.
- last_updated is missing — maintenance posture cannot be assessed; defaults to stale penalty.
Evidence
- privacy_policy_generic api Policy URL is Google account-level policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (v3.5 D).
- free_webmail_developer store developer_email=trockerapp@gmail.com, no developer_name, no business domain — reputation floor applied.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reputation discounts applied but capped under v3.5 E conditions.
- host_permissions_broad manifest <all_urls> paired with declarativeNetRequestWithHostAccess; justified-broad discount applied for PrivacyTool category.
- dom_xss_sink crx options.js: innerHTML set from variable allOpenTrackerBlocks without sanitisation. No CSP → +2.0 code quality (FIX B).
- install_url_hijack crx install_url_hijack=true but install_url_target=null; onInstalled opens URL, target unresolvable — +2.0 webstore.
- maintenance_unknown store last_updated empty, months_since_update=null; treated conservatively as 6-12mo stale (+3.5 maintenance).
- js_external_hosts crx 12 external hosts in JS including trk.klclick1.com and t.yesware.com (tracking domains); >3 distinct domains +1.5 network.
Permissions Breakdown
- declarativeNetRequest medium Can block/redirect network requests; core to tracker-blocking function.
- declarativeNetRequestFeedback medium Reads which rules matched which requests; mild info exposure.
- declarativeNetRequestWithHostAccess high Enables host-level net request interception across all URLs — HIGH capability.
- storage low Local extension storage only; low standalone risk.
- offscreen low Creates hidden offscreen document; minor capability expansion.
- <all_urls> (host) high Broad host access required for declarativeNetRequestWithHostAccess.
- *://*.google.com/* (host) medium Scoped to Google domains; content scripts active on mail.google.com.
- *://*.live.com/* (host) medium Scoped to Microsoft Live/Outlook mail domains.
- *://*.googleusercontent.com/* (host) low Google user content CDN; limited attack surface.
Pillar Scores
Permissions4.50
Reputation5.00
Network2.00
Webstore2.50
Maintenance5.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA
700cc4a05460…
Force block
— not fired
Score recovered
no
Elapsed
29.2s