FlySafe - Avoid Boeing Flights
chbkdaaihckneklhbadanlnoimmlhkii
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- <all_urls> content script on every site with innerHTML DOM-XSS sink in content.js
- Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing
- No developer name; free-webmail hotmail dev with no business domain or identity verification
- Only 7 installs but carries HIGH-tier host permission — tail attack surface anomaly flagged
- Verified-publisher badge offers limited assurance given generic privacy policy and anonymous dev identity
Evidence
- host_permissions=<all_urls> + content_scripts on all URLs manifest Extension injects content script on every site; maximum DOM read/write reach.
- dom_sink_innerhtml_userctrl in content.js crx innerHTML assigned from variable replacedText — DOM-XSS risk on all pages visited.
- privacy_policy is Google generic policy store URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer identity store No developer name; email petro.90@hotmail.com (free webmail, numbered alias pattern).
- install_perm_anomaly api 7 installs with HIGH-tier host permission; small_install_high_perm=true, tail_attack_surface=true.
- verified_publisher=true store Verified publisher badge present but generic policy and anonymous dev limit its assurance value.
- maintenance: 13 months since update store Last updated June 13 2025; 12-24mo band → +6.0 maintenance score.
- csp_present=false, MV3 manifest No CSP declared; MV3 strict default applies so no +2.0 network penalty.
Permissions Breakdown
- <all_urls> (host_permissions) high Grants content script access to every site the user visits — maximum reach.
- <all_urls> (content_scripts_matches) high Content script injected on all URLs; can read/modify any page DOM.
Pillar Scores
Permissions6.00
Reputation6.50
Network2.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-08 14:28
Listing SHA
b1db2a38abab…
Force block
— not fired
Score recovered
no
Elapsed
—