Memos
cbhjebjfccgchgbmfbobjmebjjckgofe
Risk Score
4.26
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Broad host permissions (http://*/* + https://*/*) with scripting allow code injection on every site visited.
- Privacy policy is Google's generic policy — not scoped to this extension; scope_extension==false with data_collection+third_party_sharing==true yields max privacy score.
- Developer uses free webmail (gmail) with no verified business identity, limiting accountability.
- No CSP on MV3 extension with innerHTML DOM-XSS sink in view-image.js.
- External JS hosts include tokinx.github.io — third-party GitHub Pages domain increases supply-chain risk.
Evidence
- broad_host_permissions manifest host_permissions: http://*/* and https://*/* grant access to all sites combined with scripting.
- generic_privacy_policy store Privacy URL is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email coorhook@gmail.com; no verified publisher badge; no business domain.
- dom_xss_sink crx js/view-image.js: innerHTML assigned from variable without sanitization; no CSP present.
- external_js_hosts crx js_external_hosts includes tokinx.github.io — third-party GitHub Pages, potential supply-chain vector.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- low_install_count store Only 3,000 installs; limited blast radius but tail-attack-surface noted by anomaly check.
- recently_updated store Last updated April 24, 2026 (2 months ago); maintenance risk is minimal.
Permissions Breakdown
- tabs medium Can read tab URLs and titles across all sites.
- scripting high Allows programmatic script injection into pages; paired with broad host access.
- windows low Window management; limited standalone risk.
- storage low Local data storage only; no cross-origin risk.
- activeTab low Scoped to user-activated tab; limited reach.
- contextMenus low UI integration only; no data access.
- http://*/* high Broad host access over all HTTP sites; enables scripting on any page.
- https://*/* high Broad host access over all HTTPS sites; enables scripting on any page.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA
9af2ded09b4a…
Force block
— not fired
Score recovered
no
Elapsed
23.8s