MultiPassword — Password manager
cnlhokffphohmfcddnibpohmkdfafdli
Risk Score
3.55
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Broad host access (https://*/*, http://*/*) combined with webRequest and scripting allows full page interception on every site.
- browsingData + privacy permissions grant destructive browser-state control beyond typical password manager needs.
- Privacy policy not scoped to this extension; data_collection=false but scope_extension=false — policy doesn't cover extension behavior.
- sandbox CSP contains unsafe-inline and unsafe-eval, weakening XSS mitigations in sandboxed pages.
- Three innerHTML DOM-XSS sinks in injected content scripts could be exploited if attacker-controlled data reaches them.
Evidence
- verified_publisher+featured store Extension has Google verified publisher badge and is featured — strong trust signal; reputation floored at 2.0.
- broad_host_access manifest host_permissions: https://*/*, http://*/* — full site access; justified-broad discount applied for PasswordManager category.
- sandbox_csp_unsafe manifest sandbox CSP includes unsafe-inline and unsafe-eval on script-src, weakening XSS defenses in sandboxed contexts.
- privacy_policy_not_scoped api privacy_policy_classification: fetched=true, scope_extension=false, data_collection=false → +9.0 privacy pillar.
- dom_xss_sinks crx 3 innerHTML DOM-XSS sinks found in chunks and injectContent; csp_present=true limits upgrade to +2.0 total.
- geo_diversity crx JS external hosts span 5 countries (CA,IN,NL,SG,US); +1.5 network for category not in VPN/Antivirus/etc.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
- recently_updated store Last updated March 4 2026, months_since_update=3; maintenance pillar = 0.0.
Permissions Breakdown
- unlimitedStorage low Expected for password manager storing vault data locally.
- privacy high Can modify browser privacy settings; HIGH-tier permission.
- activeTab low Limited to currently active tab on user action.
- browsingData high Can delete cookies, history, cache — significant data-erasure capability.
- clipboardWrite medium Needed for copy-password functionality; write-only.
- contextMenus low UI surface only; low risk.
- scripting medium Can inject scripts into pages; combined with broad host access is elevated.
- storage low Standard extension storage for settings/vault references.
- tabs medium Can read tab URLs and titles; moderate privacy exposure.
- offscreen low Used for background DOM operations; low standalone risk.
- webRequest high Can observe all network requests; significant surveillance capability.
- https://*/* high Broad host access across all HTTPS sites amplifies scripting+webRequest risk.
- http://*/* high Broad host access across all HTTP sites.
Pillar Scores
Permissions5.50
Reputation2.00
Network2.50
Webstore2.00
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| v3.6 | 3.55 | Low | review | 2026-06-16 |
| v3.4-rev | 3.47 | Low | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA
8a7957ecfa48…
Force block
— not fired
Score recovered
no
Elapsed
32.8s