Keyboard Shortcuts for Websites
dgigbgdgmhhncfgaidcbmafkcmagkool
Risk Score
6.21
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Extension last updated 45 months ago — zombie state with broad host access on all sites.
- Privacy policy is generic Google account policy; not scoped to this extension, admits data collection and 3rd-party sharing.
- Broad content-script host access (http://*/* + https://*/*) with no CSP — runs on every site.
- Two innerHTML DOM-XSS sinks without CSP; no-CSP amplifies risk per v3 FIX B.
- Gmail developer, small install base with high-perm anomaly flagged; no verified publisher.
Evidence
- maintenance_stale store Last updated September 2022 — 45 months ago, > 36mo threshold, scores 10.0.
- privacy_policy_generic store Policy URL is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 (v3.5 D).
- broad_host_access manifest host_permissions http://*/* + https://*/* with content_scripts on same scope.
- no_csp manifest content_security_policy is null; csp_present=false amplifies innerHTML XSS risk.
- dom_xss_sink crx innerHTML assigned from variables in popup.js and content/shortcuts.js; no CSP protection.
- gmail_developer store Developer email bhnmzm@gmail.com; free webmail, no business domain, no verified publisher.
- install_perm_anomaly api 989 installs with high-tier host permissions — small_install_high_perm and tail_attack_surface both true.
- is_featured_by_google store Featured badge present; applies -2.0 reputation discount but does not offset stale/privacy issues.
Permissions Breakdown
- activeTab low Only active tab on user gesture; limited blast radius.
- storage low Local storage for shortcut definitions; no exfil risk alone.
- http://*/* high Broad host access — content scripts run on all HTTP sites.
- https://*/* high Broad host access — content scripts run on all HTTPS sites.
Pillar Scores
Permissions5.00
Reputation6.50
Network2.00
Webstore4.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA
a4212508f62e…
Force block
— not fired
Score recovered
no
Elapsed
25.1s