Enhancer for Telegram™
dafiggkhlbbhfcpgggcfeeoliillkabn
Risk Score
5.56
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: uses Telegram™ trademark, developer is unaffiliated gmail user with no verified identity.
- Privacy policy points to Google's own policy — not scoped to this extension; data collection and third-party sharing admitted.
- Install AND uninstall URL hijack flags present; targets not captured but pattern is consistent with traffic monetization.
- Developer email is gmail with no business domain; free-webmail floor applies, reputation pillar at 7.5.
- Maintenance: 13 months since last update (6–24mo band) adds moderate staleness risk.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=['telegram'], confirmed_owner=false, developer_domain=gmail.com.
- install_url_hijack crx install_url_hijack=true, install_url_target=null. Pattern consistent with monetization shell even without captured target.
- uninstall_url_hijack crx uninstall_url_hijack=true, uninstall_url_target=null. Uninstall redirect to 3rd-party is a scored webstore risk (+3.0).
- generic_privacy_policy store Policy is Google's own account policy (scope_extension=false, data_collection=true, third_party_sharing=true) → Privacy pillar 10.0.
- free_webmail_developer store Developer email grephyr.prj@gmail.com; no business website; reputation floor 7.5 applied.
- no_csp manifest content_security_policy=null; MV3 so no +2.0 network penalty, but dom_sink risk unmitigated.
- staleness store months_since_update=13, falls in 6–24mo band → Maintenance pillar 6.0.
- operator_cluster_dev_email_siblings api sibling_count=0 (compound), but dev_email dimension shows 4 sibling extensions under same gmail address.
Permissions Breakdown
- storage low Stores extension settings locally; no cross-site data risk.
- content_scripts *://*.web.telegram.org/* medium Injects JS into Telegram Web; scoped to one origin but can read page content.
Pillar Scores
Permissions1.30
Reputation7.50
Network0.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA
d8714d008991…
Force block
— not fired
Score recovered
no
Elapsed
20.8s