AI Compare — multi-AI compare for QA & GEO
dkhpgbbhlnmjbkihoeniojpkggkabbbl
Risk Score
4.43
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own generic policy (myaccount.google.com) — not scoped to this extension; effectively no extension-specific disclosure.
- Free webmail dev email (outlook.com) with no verified publisher badge; accountability gap.
- Content scripts injected on all URLs plus clipboardRead enables broad data access across every site visited.
- Three innerHTML DOM-XSS sinks with user-controlled input on an extension with <all_urls>; exploitable via malicious page content.
- Contacts raw.githubusercontent.com and Firebase Cloud Functions — remote code/config loading risk from developer-controlled but mutable endpoints.
Evidence
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers D hardening (+10).
- free_webmail_dev store Developer email AIShortcuts@outlook.com is free webmail; no verified publisher; reputation floor raised to 7.5.
- broad_host_access manifest <all_urls> host permission + content_scripts on all URLs; extension reads/modifies every page visited.
- dom_xss_sinks crx 3 innerHTML sinks with user-controlled variables in inject.js, sidebar.js, extraction-core.js; CSP present but sandbox has unsafe-eval.
- sandbox_unsafe_eval manifest CSP sandbox page allows unsafe-eval, enabling dynamic code execution in sandboxed context.
- external_hosts_mutable crx raw.githubusercontent.com and us-central1-aicompare-12989.cloudfunctions.net contacted; mutable remote config risk.
- google_analytics crx www.google-analytics.com contacted; telemetry-tier monetization hit; AI extension processing page content.
- ai_page_content store AI extension with <all_urls> content scripts; processes and compares page content across sites (+2.5 webstore).
Permissions Breakdown
- storage low Stores local extension state; low risk alone.
- activeTab low Scoped to user-invoked tab only.
- tabs medium Access to tab URLs/titles across all tabs.
- contextMenus low Adds right-click menu items; low risk.
- declarativeNetRequest medium Can modify network requests declaratively.
- sidePanel low Opens side panel UI; low risk.
- clipboardRead medium Reads clipboard content without user gesture.
- omnibox medium Intercepts address bar input.
- identity low OAuth token access; limited without scopes.
- <all_urls> high Content scripts injected on every site; broad reach.
Pillar Scores
Permissions6.50
Reputation7.50
Network5.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:25
Listing SHA
702807e0ff32…
Force block
— not fired
Score recovered
no
Elapsed
—