AT Price Tracker (Working August 2026)
cbecfdegmcppmbpbffdpagongfpbohmd
Risk Score
4.31
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope to this extension at all (D rule: fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0).
- Uninstall URL hijack flag set; uninstall redirect target not captured but signal indicates external redirect attempt.
- No developer name, email, or verified publisher; anonymous extension with no accountability.
- Content script injected into third-party domain at.liprock.com with no clear stated purpose — unknown backend.
- identity.email permission collects Google account email, enabling persistent user identification with no scoped disclosure.
Evidence
- privacy_policy_generic store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → privacy pillar +10.0.
- uninstall_url_hijack crx uninstall_url_hijack=true in manifest; target null but flag indicates external redirect on uninstall.
- install_url_hijack crx install_url_hijack=true; onInstalled opens onboarding.html (internal page, lower risk).
- anonymous_developer store developer_name, developer_email all empty; no verified_publisher; reputation floor applies.
- third_party_content_script manifest Content script on https://at.liprock.com/* — unknown third-party domain not explained by stated function.
- identity_email_permission manifest identity.email grants read access to user's Google account email address.
- no_csp crx csp_present=false on MV3; MV3 has strict default so no v2 penalty applied.
- maintenance_unknown api months_since_update=null; last_updated missing; maintenance pillar scored 0 (no penalty, no data).
Permissions Breakdown
- identity low OAuth identity access; no scopes declared, limited impact alone.
- identity.email medium Reads user's Google email address; enables user tracking/profiling.
- storage low Local extension storage; standard for preference/cache persistence.
- content_scripts: *://*.autotrader.co.uk/* medium Script injected into all autotrader.co.uk pages; can read page content.
- content_scripts: https://at.liprock.com/* medium Script injected into unknown third-party domain at.liprock.com.
Pillar Scores
Permissions2.30
Reputation7.50
Network0.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiedn3af898f1dp727562726963xsx | 4.35 | Medium | review | 2026-08-26 |
| v3.6 | 4.31 | Medium | review | 2026-08-06 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-06 05:35
Listing SHA
43ce163c21d1…
Force block
— not fired
Score recovered
no
Elapsed
—