Word Counter
dcdjbggikbffllfldmdijljoljjbjomh
Risk Score
6.27
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Install and uninstall URL hijack via bit.ly short-links — cloaks final destination from security tools.
- Privacy policy is Google's generic account policy; does not scope to this extension at all (collects+shares data per classification).
- Free-webmail developer (gmail) with no verifiable business identity; low accountability.
- <all_urls> host permission grants content-script read access on every site visited.
- 17-month-stale extension with bit.ly affiliate hit and unverifiable developer domain raises supply-chain concern.
Evidence
- install_url_hijack crx onInstalled opens https://bit.ly/wcextni — cloaked redirect to unknown 3rd-party destination.
- uninstall_url_hijack crx setUninstallURL points to https://bit.ly/wcextnui — 3rd-party redirect on uninstall.
- affiliate_hit_bit.ly crx js_external_hosts includes bit.ly; threat_intel flags it as affiliate/cloaking short-link redirector.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email extensiongadget@gmail.com; no business domain; domain_age_ct not queried (free webmail).
- host_permission_all_urls manifest <all_urls> in host_permissions with content_scripts_matches also <all_urls> — runs on every page.
- tail_attack_surface api install_perm_anomaly: tail_attack_surface=true, has_high_tier_permission=true, only 3000 installs.
- stale_maintenance store Last updated January 2025; 17 months since update — approaching 18-month stale threshold.
Permissions Breakdown
- contextMenus low Standard context menu integration; minimal standalone risk.
- tabs medium Can read tab URLs and metadata; moderate risk paired with host access.
- <all_urls> (host_permission) high Content scripts run on every site; broad reach for a word-counter tool.
Pillar Scores
Permissions5.50
Reputation7.00
Network2.50
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA
dd8ae9a8870c…
Force block
— not fired
Score recovered
no
Elapsed
24.0s