AI Blaze: Instantly Use AI in Any Webpage
cebmnlammjhancocbbnfcglifgdpfejc
Risk Score
3.31
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false and third_party_sharing=true — data handling for this extension is not scoped.
- AI extension processes page content; data-exfil surface cannot be verified without CRX scan.
- manifest_source=html_fallback: actual permissions undetermined — capabilities not auditable.
- No developer name; identity accountability gap raises reputation score.
- No verified publisher badge; featured discount applied but publisher identity unconfirmed.
Evidence
- privacy_policy_scope_mismatch api Policy fetched but scope_extension=false, data_collection=false, third_party_sharing=true → +9.0 privacy (v3 FIX A).
- manifest_source_html_fallback store manifest_source=html_fallback; no CRX permissions parsed — install_count=90k below 100k threshold, no empty-manifest bonus.
- ai_extension_page_content store Title explicitly AI; processes webpage content — inherent data-exfil surface.
- no_developer_name store developer_name empty; +1.0 reputation for missing Offered-by identity.
- featured_by_google store is_featured_by_google=true; applies -2.0 featured discount on reputation.
- no_bad_hosts_no_monetization api threat_intel: bad_host_hits=[], monetization_hits=[], affiliate_hits=[] — clean.
- code_scan_unavailable crx js_files_scanned=0, code_findings_raw=[], obfuscation_score=0.0 — no CRX surface.
- recently_updated store months_since_update=3; maintenance pillar = 0.0.
Pillar Scores
Permissions0.00
Reputation5.50
Network0.00
Webstore3.50
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA
a50befc9241c…
Force block
— not fired
Score recovered
no
Elapsed
20.1s