Glasp Web Highlighter: PDF & Web Highlight
blillmbchncajnhkjfdnincfndboieik
Risk Score
4.83
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetch failed — no confirmed disclosure of data handling for 500K users.
- brand_mention.is_impersonation=true (YouTube, ChatGPT, Claude, Gemini) without verified ownership.
- Broad host_permissions *://* + content_scripts <all_urls> enables reading every page visited.
- 7 external JS hosts (chatgpt.com, gemini.google.com, twitter.com, etc.) beyond own domain — wide network surface.
- new Function() constructor in background bundle and PDF libs raises code-execution concern.
Evidence
- broad_host_permissions manifest host_permissions: *://*/* combined with content_scripts on <all_urls> — runs on every page.
- privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError); privacy pillar scored at max.
- brand_impersonation store brand_mention.is_impersonation=true; mentions YouTube, ChatGPT, Claude, Gemini; confirmed_owner=false.
- external_hosts crx 8 external hosts including chatgpt.com, gemini.google.com, twitter.com, facebook.com, linkedin.com.
- function_constructor_in_background crx new Function() found in background.bundle.js — dynamic code execution risk in privileged context.
- featured_by_google store is_featured_by_google=true; applies -2.0 featured discount to reputation pillar.
- no_developer_name store developer_name is empty string; only dev email hi@glasp.co present.
- cve_clean crx cve_findings_raw is empty; jquery 3.7.1 is current; no CVE exposure.
Permissions Breakdown
- activeTab low Temporary access to current tab on user action; low blast radius.
- contextMenus low Adds right-click menu items; no data exfil risk alone.
- tabs medium Can read tab URLs and titles across all tabs.
- storage low Local/sync key-value store; no direct exfil path.
- *://*/* (host_permissions) high Broad host access enables content script injection on every page visited.
- content_scripts <all_urls> high Scripts run on every page; combined with broad host perm amplifies risk.
Pillar Scores
Permissions5.50
Reputation5.50
Network3.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA
a4967a12c1af…
Force block
— not fired
Score recovered
no
Elapsed
25.3s