YouNativefy
copobeiecgdaejfmkgadefmhhhbohike
Risk Score
4.33
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL returns fetch error — effectively no accessible privacy policy for 13-install extension contacting GCP backend.
- Multiple innerHTML DOM-XSS sinks in content scripts on Netflix, Prime, YouTube without CSP to mitigate.
- new Function() constructors in bundled node_modules (ajv, webpack) with no CSP — amplifies injection risk.
- Brand impersonation signal: extension names/describes YouTube, Netflix, Disney+ without confirmed ownership.
- Free-webmail dev email (gmail), no developer name disclosed; low accountability for backend data handling.
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false; HTTPError fetching https://younativefy.com.br/privacy → scored as no policy.
- brand_impersonation store brand_mention: disney/youtube/netflix mentioned; confirmed_owner==false; is_impersonation==true.
- dom_xss_no_csp crx 4 innerHTML sinks in content scripts + popup; csp_present==false; MV3 default CSP applies but no explicit extension CSP.
- function_constructor_node_modules crx 6 new Function() hits in ajv, tapable, terser, webpack node_modules; likely build artifacts but bundled into CRX.
- developer_identity_weak store developer_name empty; developer_email is free Gmail; no business domain verified.
- backend_endpoint manifest host_permissions include younativefy-backend-800430356291.us-central1.run.app; data sent to GCP run app.
- verified_publisher store verified_publisher==true; partially mitigates reputation risk but no featured badge.
- low_install_count store Only 13 installs; operator_cluster sibling_count==0; limited blast radius but tail-attack surface.
Permissions Breakdown
- activeTab low Scoped to user-initiated tab interaction only.
- storage low Local data persistence; limited risk.
- contextMenus low UI surface only; no data access.
- host:youtube/netflix/disney+/max/amazon/primevideo medium Content scripts on major streaming platforms; broad but matches stated language-learning function.
- host:younativefy-backend medium Calls dev-controlled backend; data sent to GCP endpoint without disclosed privacy policy.
Pillar Scores
Permissions2.50
Reputation6.00
Network2.50
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:31
Listing SHA
d57028dd94dd…
Force block
— not fired
Score recovered
no
Elapsed
—