Sticky Password manager & safe
bnfdmghkeppfadphbnkjcicejfepnbfe
Risk Score
4.77
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetch failed — privacy posture completely unknown; 10.0 privacy pillar score.
- nativeMessaging with unrecognized publisher bridges extension to OS-level companion app (+3.0 perm).
- Broad content scripts on all HTTP/HTTPS pages give full DOM access on every site visited.
- innerHTML DOM-XSS sink in spUninstall.js; CSP present but user-controlled value assignment is risky.
- No developer name listed; rating 3.9 without count context reduces reputation confidence.
Evidence
- nativeMessaging_unrecognized_publisher crx native_messaging_check.publisher_recognized=false; companion app can execute arbitrary OS code.
- privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError); policy content unverifiable → +10.0.
- broad_content_scripts manifest content_scripts_matches includes http://*/* and https://*/* — runs on every HTTP/HTTPS page.
- dom_xss_sink crx spUninstall.js: innerHTML assigned from variable AValue — DOM-XSS risk, CSP present mitigates somewhat.
- no_developer_name store developer_name is empty string; no 'Offered by' identity for attribution.
- no_bad_hosts_no_affiliates api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — clean threat intel.
- csp_present_mv3 manifest script-src 'self'; object-src 'self' — strict CSP, MV3, no unsafe-eval/inline.
- js_external_hosts_reference_only crx 12 external hosts in JS all appear to be documentation/spec references (github, MDN, W3C, etc.).
Permissions Breakdown
- privacy high Can read/write browser privacy settings — broad control over user privacy configuration.
- tabs medium Access to tab URLs and metadata — needed for autofill but enables browsing history inference.
- storage low Local credential/settings persistence — expected for a password manager.
- notifications low Can push desktop notifications — low standalone risk.
- nativeMessaging high Bridges to companion desktop app; publisher not recognized — high privilege escalation path.
- content_scripts http://*/* https://*/* high Broad content script injection on all HTTP/HTTPS pages — full DOM read/write on every site.
Pillar Scores
Permissions7.00
Reputation5.50
Network0.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA
c72b6033a43b…
Force block
— not fired
Score recovered
no
Elapsed
25.1s