GPTSubs — X Premium Helper
chhbknablgnpbjokiakabbaekeohooec
Risk Score
4.32
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies + scripting on x.com/twitter.com enables full session token theft with no CSP guard.
- Developer is free-webmail Gmail user with no verified identity or business website.
- Privacy policy fetched but scope_extension=false and third_party_silence=true — effectively undisclosed.
- DOM-XSS sink (innerHTML) in popup.js with no CSP; amplifies any injection vulnerability.
- Small-install + high-perm anomaly (34 installs, cookies+scripting+host access) — tail attack surface.
Evidence
- cookies+scripting+host_permissions on x.com manifest cookies + scripting + https://x.com/* + https://twitter.com/* allows full session read/write on social platform.
- no CSP declared crx csp_present=false; MV3 has strict default but no explicit policy; DOM-XSS sink unmitigated.
- free-webmail developer email store lucky.eagle100@gmail.com — numbered-alias pattern on Gmail, no verified business identity.
- privacy policy inadequate api scope_extension=false, data_collection=false, third_party_silence=true — policy doesn't cover this extension.
- dom_sink_innerhtml_userctrl in popup.js crx innerHTML assigned from variable without sanitization — DOM-XSS risk, no CSP mitigates.
- install_perm_anomaly api Only 34 installs with HIGH-tier permissions (cookies + scripting + broad host) — tail attack surface.
- privacy policy on .ru domain store gptsubs.ru — elevated-risk TLD for privacy policy hosting, no scope to this extension.
- no verified publisher / featured badge store verified_publisher=false, is_featured_by_google=false — no accountability signals.
Permissions Breakdown
- cookies high Can read/write cookies on x.com/twitter.com — sensitive auth token exposure risk.
- clipboardWrite medium Can write to clipboard; limited scope but could inject malicious content.
- activeTab low Scoped to user-activated tab; limited reach.
- scripting medium Can inject scripts into x.com/twitter.com pages; combined with cookies raises risk.
- https://x.com/* high Broad host access to X.com; combined with cookies allows full session capture.
- https://twitter.com/* high Broad host access to Twitter.com; same session-capture risk as x.com.
Pillar Scores
Permissions4.50
Reputation6.50
Network2.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:20
Listing SHA
601e9706c0d9…
Force block
— not fired
Score recovered
no
Elapsed
—