AutoHD for Twitch™
didbenpmfaidkhohcliedfmgbepkakam
Risk Score
6.24
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Twitch brand impersonation by unverified developer 'karsten' with no confirmed ownership of the mark.
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- declarativeNetRequestWithHostAccess + https://*/*: can intercept and modify requests on all HTTPS sites.
- Content scripts injected on <all_urls> with no CSP; DOM-XSS sink (innerHTML) present in popup JS.
- Extension last updated 18 months ago; at boundary of stale classification with high-capability permissions.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'twitch'; developer domain autohd.org not confirmed owner.
- generic_privacy_policy store Privacy policy URL is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
- broad_host_access manifest host_permissions=['https://*/*'] + content_scripts on <all_urls> + declarativeNetRequestWithHostAccess.
- dom_xss_sink crx code_findings_raw: dom_sink_innerhtml_userctrl in popup.100f6462.js; no CSP present (MV3 default only).
- stale_extension store months_since_update=18; at 18mo boundary with HIGH-tier permissions active.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 1,000 installs with HIGH-tier permissions increases supply-chain risk.
- external_js_host crx js_external_hosts=['reactjs.org']; external JS reference present though no bad-host hits detected.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false; single-name dev 'karsten' with no org backing.
Permissions Breakdown
- storage low Stores user preferences locally; minimal risk.
- tabs medium Can read tab URLs and titles; moderate privacy surface.
- declarativeNetRequestWithHostAccess high Can intercept/modify network requests across all HTTPS sites.
- https://*/* high Broad host access pairs with declarativeNetRequestWithHostAccess — high capability.
- content_scripts:<all_urls> high Injects scripts into every page; large attack surface for DOM manipulation.
Pillar Scores
Permissions7.50
Reputation7.00
Network2.50
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:06
Listing SHA
5b2853cb1280…
Force block
— not fired
Score recovered
no
Elapsed
—