Star's Youtube Music Mini Player
bkdemnjphbdblmbjlemmjkhcaalhkjnd
Risk Score
4.72
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- YouTube brand mentioned in name/title without confirmed ownership (impersonation flag).
- innerHTML assignment from variable in content-script.js is a DOM-XSS sink with no CSP to mitigate.
- Developer uses free-webmail address (live.com); no verified publisher badge.
- Last updated 13 months ago; no changelog visibility.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'youtube'; developer_domain live.com not confirmed owner.
- privacy_policy_generic api Policy is Google's generic account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
- dom_xss_sink crx content-script.js: innerHTML assigned from variable; no CSP present → elevated DOM-XSS risk.
- no_csp manifest content_security_policy is null; MV3 applies strict default but no explicit CSP declared.
- free_webmail_dev store Developer email uriel_villanueva@live.com; live.com is free-webmail; no verified publisher.
- maintenance_stale store months_since_update=13; falls in 12-24mo band (+6.0 maintenance).
- host_permissions_narrow manifest host_permissions limited to *://music.youtube.com/* — matches stated mini-player function.
- no_bad_hosts_or_monetization api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — clean network intel.
Permissions Breakdown
- activeTab low Grants access to active tab only on user gesture; scoped to music.youtube.com.
- tabs medium Can read tab URLs/titles; needed for mini-player but broader than activeTab alone.
- scripting medium Can inject scripts; combined with host_permissions limited to music.youtube.com.
- *://music.youtube.com/* low Narrow host scope; limited to YouTube Music only, matches stated function.
Pillar Scores
Permissions2.30
Reputation6.50
Network2.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| sssiedn832df47cdp727562726963xsx | 4.49 | Medium | review | 2026-08-27 |
| v3.6 | 4.72 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA
95291ec2a97b…
Force block
— not fired
Score recovered
no
Elapsed
22.3s