Super Focus Tabs
blecebkjfbkpannnmajllilknpccheak
Risk Score
6.16
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; third-party sharing admitted without extension context.
- Extension stale for 36 months with <all_urls> content scripts and history/bookmarks access — high abandonment/takeover risk.
- Developer is free-webmail gmail user with no business identity; no verified publisher badge.
- install_url_hijack flag set — onInstalled may open an untracked third-party URL.
- CSP sandbox profile allows unsafe-eval and unsafe-inline, weakening script isolation.
Evidence
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; scope_extension=false, third_party_sharing=true.
- stale_extension store Last updated June 2023; months_since_update=36 — at maintenance boundary, high abandonment risk.
- free_webmail_developer store developer_email=nghiai3e@gmail.com; no business domain, no verified publisher, no featured badge that overrides reputation floor.
- install_url_hijack crx install_url_hijack=true; target null — onInstalled opens external URL, possible traffic monetization.
- dom_xss_sink crx scripts/Interface.min.js: innerHTML assigned from tab-count variable; DOM-XSS risk though CSP extension_pages is strict.
- sandbox_csp_unsafe crx Sandbox CSP allows unsafe-eval and unsafe-inline on script-src, reducing XSS protection in sandboxed context.
- host_permission_all_urls manifest <all_urls> in host_permissions + content_scripts_matches; combined with history and bookmarks is high-reach capability.
- telemetry_only_network crx js_external_hosts: google.com, www.google-analytics.com only; single US geo; no bad-host hits.
Permissions Breakdown
- tabs medium Access to tab URLs and titles across all open tabs.
- storage low Standard local data persistence.
- alarms low Scheduled background tasks; minimal risk.
- contextMenus low Adds right-click menu entries; low risk.
- history medium Can read and modify full browsing history.
- bookmarks medium Can read and modify all bookmarks.
- unlimitedStorage low Allows large local storage; no direct privacy risk.
- favicon low Access to tab favicons; minimal risk.
- system.display low Read display configuration; minimal risk.
- <all_urls> (host) high Content scripts run on every page; broad reach combined with history/bookmarks.
Pillar Scores
Permissions6.00
Reputation7.00
Network2.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA
73fe7e628145…
Force block
— not fired
Score recovered
no
Elapsed
25.7s