NordPass® Password Manager & Digital Vault
eiaeiblijfjekdanodkjadfinkhbfgcd
Risk Score
3.33
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetch failed (HTTP error); cannot verify scope or data handling — scored as no policy.
- Broad host permissions (http://*/*, https://*/*) with scripting and webRequest grant full-page access on every site.
- Privacy pillar scores maximum due to unverifiable policy, but this is a fetch artifact not confirmed bad practice.
- webRequest + broad host access without blocking capability is still high-capability for a credential-handling extension.
- Not verified_publisher on Web Store despite being a recognized commercial product; featured badge partially offsets.
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false due to fetch_error:HTTPError; scored +10.0 per rubric (fetched==false).
- featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied (Follows recommended practices badge).
- broad_host_permissions manifest host_permissions=['http://*/*','https://*/*'] plus content_scripts on same scope; justified for password manager autofill.
- no_code_findings crx code_findings_raw=[] and obfuscation_score=0.0; 113 JS files scanned cleanly.
- no_cve_findings crx cve_findings_raw=[]; no bundled vulnerable libraries detected.
- no_threat_intel_hits api bad_host_hits=[], affiliate_hits=[], monetization_hits=[]; developer domain nordpass.com resolves and not throwaway.
- high_install_good_rating store 7,000,000 installs, rating 4.6; no review red flags detected (match_count=0).
- justified_broad_discount manifest Category=Security/PasswordManager; -1.5 justified-broad-permission discount applied to permissions pillar.
Permissions Breakdown
- alarms low Used for periodic session/token refresh tasks.
- contextMenus low Adds right-click fill options; standard for password managers.
- idle low Detects inactivity for auto-lock; expected in password managers.
- privacy high Can modify Chrome privacy settings; powerful but expected for security tools.
- storage low Stores encrypted vault data locally.
- tabs medium Reads active tab URL for credential matching; standard for autofill.
- webNavigation medium Monitors navigation events to trigger autofill on page load.
- webRequest high Observes network requests; justified for form-detection but elevated capability.
- offscreen low Used for background crypto operations without visible UI.
- scripting medium Injects autofill scripts into pages; required for credential filling.
- http://*/* high Broad host access across all HTTP sites for autofill injection.
- https://*/* high Broad host access across all HTTPS sites for autofill injection.
Pillar Scores
Permissions4.50
Reputation2.50
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| v3.69886"();}]9009 | 3.14 | Low | review | 2026-08-05 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 3.09 | Low | review | 2026-08-05 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 2.88 | Low | review | 2026-08-05 |
| v3.6&n937533=v957363 | 3.25 | Low | review | 2026-08-05 |
| v3.6</script><script>FUBG(9214)</script> | 3.06 | Low | review | 2026-08-04 |
| dfb__${98991*97996}__::.x | 2.84 | Low | review | 2026-08-04 |
| bfg8293<s1﹥s2ʺs3ʹhjl8293 | 3.08 | Low | review | 2026-08-04 |
| v3.6&n914483=v972893 | 3.09 | Low | review | 2026-08-04 |
| <fsssiedxa sssiedx | 3.54 | Low | review | 2026-08-03 |
| xx pfsssiedxasssiedx | 3.10 | Low | review | 2026-08-03 |
| "fsssiedxa xx psssiedx | 3.46 | Low | review | 2026-08-03 |
| %22fsssiedxa$'sssiedx | 3.21 | Low | review | 2026-08-03 |
| %27fsssiedxa sssiedx | 3.05 | Low | review | 2026-08-03 |
| 'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.00 | Low | review | 2026-08-03 |
| "fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.41 | Low | review | 2026-08-03 |
| $"fsssiedxa"sssiedx | 3.34 | Low | review | 2026-08-03 |
| fsssiedxa$"sssiedx | 3.07 | Low | review | 2026-08-03 |
| v3.6"><script>tbvF(9626)</script> | 3.36 | Low | review | 2026-07-29 |
| v3.6"onmouseover=tbvF(90682)" | 2.73 | Low | review | 2026-07-29 |
| bfgx7346%C0%BEz1%C0%BCz2a%90bcxhjl7346 | 3.26 | Low | review | 2026-07-29 |
| <th:t="${dfb}#foreach | 3.16 | Low | review | 2026-07-29 |
| {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hittfbyowbcxle308f.bxss.me")}} | 3.47 | Low | review | 2026-07-29 |
| v3.6&n910418=v906344 | 3.02 | Low | review | 2026-07-29 |
| fsssiedxa sssiedx | 3.04 | Low | review | 2026-07-28 |
| fsssiedxa"sssiedx | 2.96 | Low | review | 2026-07-28 |
| fsssiedxa | 3.06 | Low | review | 2026-07-28 |
| fsssiedxa$'sssiedx | 3.14 | Low | review | 2026-07-28 |
| sssieddrubricxsx | 3.11 | Low | review | 2026-07-28 |
| v3.6 | 3.33 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
ac4d7d0141ba…
Force block
— not fired
Score recovered
no
Elapsed
25.6s