Discord Web Quest Completer
cgmommddnakeciakhimlbadjneifegng
Risk Score
4.49
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: extension name/function references Discord without being an official or verified Discord product.
- Privacy policy is Google's own generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
- Free-webmail developer (gmail.com) with no verified business identity or developer name.
- declarativeNetRequestWithHostAccess + scripting on discord.com allows intercepting/modifying all Discord traffic.
- No CSP declared (MV3 defaults apply, but youtube.com appears in external hosts fingerprint without clear justification).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[discord]; confirmed_owner=false; developer is gmail user.
- free_webmail_developer manifest developer_email=gfxeye@gmail.com; no business website; no developer name listed.
- privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
- high_permissions manifest declarativeNetRequestWithHostAccess + scripting on https://discord.com/* enables full request interception and script injection.
- js_external_host_youtube crx js_external_hosts=[www.youtube.com]; unclear why a Discord quest completer references YouTube JS.
- no_cve_no_code_findings crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0; no malicious code detected.
- recently_updated store last_updated=January 30, 2026; months_since_update=0; maintenance risk is minimal.
- install_count store 20,000 installs; modest reach but non-trivial for a niche Discord automation tool.
Permissions Breakdown
- declarativeNetRequestWithHostAccess high HIGH permission; can intercept/modify network requests to discord.com.
- scripting high Can inject arbitrary scripts into pages; scoped to discord.com but still high-risk.
- activeTab low Grants access only to the currently active tab on user gesture.
- host:https://discord.com/* medium Scoped host access to Discord; enables scripting+network interception on the platform.
Pillar Scores
Permissions5.00
Reputation7.50
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 14:04
Listing SHA
1ceef9cd9f03…
Force block
— not fired
Score recovered
no
Elapsed
20.9s