Invite fans and post likers in Facebook™
eiamkpbeehcnmbilkjkflelnendbmmhi
Risk Score
3.56
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Brand impersonation: uses Facebook™ trademark; confirmed_owner=false yet is_impersonation=true.
- No developer name disclosed; only an email under invitelikecomment.com.
- scripting + host_permissions on *.facebook.com enables JS injection into user Facebook sessions.
- No CSP (MV3 strict default mitigates, but no explicit policy declared).
- Privacy policy lacks retention disclosure and is silent on third-party sharing.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[facebook]; confirmed_owner=false.
- no_developer_name store developer_name is empty string; identity relies solely on email info@invitelikecomment.com.
- host_permissions_facebook manifest host_permissions=['https://*.facebook.com/*']; scripting permission enables JS injection.
- verified_publisher store verified_publisher=true; provides some accountability but does not override impersonation risk.
- privacy_policy_gaps api scope_extension=true, data_collection=false, retention=false, third_party_silence=true.
- js_external_hosts crx 7 external hosts referenced (bugzilla.mozilla.org, learn.jquery.com, www.invitelikecomment.com, etc.).
- no_csp manifest content_security_policy=null; MV3 strict default applies but no explicit policy set.
- jquery_version crx jquery@3.5.1 bundled; no CVEs found in cve_findings_raw; no CSP but MV3 mitigates.
Permissions Breakdown
- storage low Local state persistence; low standalone risk.
- activeTab medium Grants transient access to current tab; combined with scripting raises scope.
- scripting medium Allows programmatic JS injection into pages; powerful when paired with host_permissions.
- alarms low Background scheduling only; minimal direct risk.
- https://*.facebook.com/* high Broad host access to all Facebook subdomains; enables reading session data and DOM.
Pillar Scores
Permissions3.50
Reputation6.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy6.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
9d9295c3fa04…
Force block
— not fired
Score recovered
no
Elapsed
20.4s