Multi Find: Search and Highlight
dffaiikpbncahnghlfnkhagffaemhgfo
Risk Score
3.28
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic policy (not scoped to this extension) yet admits data collection and third-party sharing — score elevated to 10.0.
- Content scripts injected on all URLs (http, https, file) gives broad page-read capability despite minimal declared permissions.
- install_url_hijack flag is true with no visible target — warrants manual verification of onInstalled behavior.
- Developer name field is empty; no 'Offered by' display name beyond email domain vgreco.fr.
- No CSP defined (MV3 default applies but absence of explicit policy is noted alongside broad content-script reach).
Evidence
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; scope_extension=false, data_collection=true, third_party_sharing=true.
- content_scripts_all_urls manifest content_scripts_matches covers file://*/* http://*/* https://*/* — full-page access on every site visited.
- install_url_hijack crx install_url_hijack=true but install_url_target=null; onInstalled redirect detected, destination unresolved.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reputation floor applied at 2.0.
- no_developer_name store developer_name is empty string; only identifier is info@vgreco.fr on resolving domain vgreco.fr.
- no_cve_no_bad_hosts crx cve_findings_raw=[], bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — clean threat intel.
- clean_code_scan crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[] — no malicious code indicators.
- install_count_reach store 100,000 installs; moderate blast radius if extension were compromised or sold.
Permissions Breakdown
- storage low Stores extension settings locally; low-impact API.
- contextMenus low Adds right-click menu items; no data exfil surface alone.
- content_scripts <all_urls> medium Runs scripts on every http/https/file URL; broad page access for a search tool.
Pillar Scores
Permissions2.30
Reputation2.00
Network0.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA
b1214dd6b602…
Force block
— not fired
Score recovered
no
Elapsed
22.2s