YouTube High Definition
dokdlgjaaaijndfajoknjbelmadhomca
Risk Score
4.61
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- YouTube brand impersonation: developer is unverified yahoo.com user with no dev name.
- host_permissions <all_urls> while content_scripts only cover youtube.com — scope mismatch grants unnecessary broad access.
- Extension stale 21 months with no CSP, increasing future-compromise attack surface.
- Free-webmail developer (yahoo.com), no business identity, no developer name disclosed.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'youtube'; developer is yahoo.com free-webmail user with no org affiliation.
- generic_privacy_policy store Privacy policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — D clause triggers +10.0.
- host_permission_all_urls manifest <all_urls> host permission declared; content_scripts only target youtube.com — scope mismatch.
- no_csp manifest content_security_policy is null; MV3 has strict default but getbootstrap.com loaded as external JS host.
- free_webmail_dev_no_name store developer_email=barisderin@yahoo.com, developer_name empty, no business website.
- stale_21_months store Last updated Sep 2024; 21 months since update triggers +6.0 maintenance base.
- external_js_host crx js_external_hosts includes getbootstrap.com — third-party JS origin loaded by extension.
- verified_publisher_capped store verified_publisher=true but 0c cap applies: months_since_update=21 (>18), so discount capped at -1.0.
Permissions Breakdown
- storage low Stores extension preferences locally; low standalone risk.
- <all_urls> (host_permission) high Content scripts injected on all URLs; broad access beyond stated YouTube scope.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| <fsssiedx{ xx psssiedx | 5.19 | Medium | review | 2026-08-20 |
| <fsssiedx{ | 4.43 | Medium | review | 2026-08-20 |
| <fsssiedx{$"sssiedx | 5.18 | Medium | review | 2026-08-20 |
| <fsssiedxhfdsaxax><!--></ScRiPt>asddsssiedx | 5.17 | Medium | review | 2026-08-20 |
| <fsssiedxh | 5.28 | Medium | review | 2026-08-20 |
| <fsssiedxh$"sssiedx | 5.09 | Medium | review | 2026-08-20 |
| xx pfsssiedxmfdsaxax><!--></ScRiPt>asddsssiedx | 5.39 | Medium | review | 2026-08-20 |
| "fsssiedxm xx psssiedx | 4.48 | Medium | review | 2026-08-20 |
| %27fsssiedxm"sssiedx | 5.37 | Medium | review | 2026-08-20 |
| %27fsssiedxm$"sssiedx | 4.30 | Medium | review | 2026-08-20 |
| 'fsssiedxm$'sssiedx | 5.24 | Medium | review | 2026-08-20 |
| "fsssiedxm sssiedx | 4.66 | Medium | review | 2026-08-20 |
| <fsssiedxm sssiedx | 5.08 | Medium | review | 2026-08-20 |
| fsssiedxm<sssiedx | 5.01 | Medium | review | 2026-08-20 |
| fsssiedxa xx psssiedx | 5.36 | Medium | review | 2026-08-20 |
| fsssiedxa | 5.49 | Medium | review | 2026-08-20 |
| sssieddrubricxsx | 5.07 | Medium | review | 2026-08-20 |
| v3.6 | 4.61 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.86 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA
afb8bc639938…
Force block
— not fired
Score recovered
no
Elapsed
20.2s