Microsoft Defender Browser Protection
bkbeeeffjjeopflfhgeknacdieedcoml
Risk Score
3.09
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy (not scoped to this extension); admits data collection and 3rd-party sharing without extension-specific disclosure.
- Extension is 16 months stale; approaching the 18-month threshold for verified-publisher cap reduction.
- No developer display name in store listing despite verified publisher badge.
- webNavigation + tabs combination enables full URL observation of every page visit sent to SmartScreen.
Evidence
- privacy_policy_generic store Policy URL is myaccount.google.com — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true. Triggers +10.0 privacy (D rule).
- verified_publisher store Microsoft verified publisher; developer domain microsoft.com resolves. Reputation pillar floored at 2.0.
- recognized_org store Microsoft is a recognized org. -2.0 discount applies; no HIGH-capability gate trigger (no broad host/webRequest/debugger).
- months_since_update store Last updated Feb 2025, 16 months ago. Maintenance +3.5 (6–12mo band boundary at 12, 16mo falls in 12–24 range → +6.0).
- no_cve_no_obfuscation crx cve_findings_raw empty, code_findings_raw empty, obfuscation_score=0.0. Code quality and CVE pillars at 0.
- js_external_hosts crx Contacts bf.smartscreen.microsoft.com, feedback.smartscreen.microsoft.com, go.microsoft.com, www.bing.com — all Microsoft-owned; no bad/monetization hits.
- strict_csp manifest CSP: script-src 'self'; object-src 'self'. No unsafe-eval/inline. MV3 default protections apply.
- install_count_signal store 2,000,000 installs. +1.0 (>10K) +1.0 (>100K) in Webstore, partially offset by category fit discount context.
Permissions Breakdown
- tabs medium Can read tab URLs and titles; needed for URL-based threat detection.
- storage low Stores local config/settings; no cross-origin risk.
- webNavigation medium Monitors navigation events; fits security/phishing-check use case.
- https://*.smartscreen.microsoft.com/* low Scoped to Microsoft SmartScreen only; matches stated security function.
Pillar Scores
Permissions1.50
Reputation2.00
Network0.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA
7f1fe71ec018…
Force block
— not fired
Score recovered
no
Elapsed
23.8s