Volume Booster
ejkiikneibegknkgimmihdpcbcedgmpo
Risk Score
5.01
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, yet admits data collection and third-party sharing (Privacy pillar 10.0).
- Uninstall URL hijacks to jointoucan.com affiliate link — classic monetization shell signal (+3.0 Webstore).
- Broad host permissions (<all_urls> tripled) paired with tabCapture enables full audio/page capture on every site visited.
- Developer email is free-webmail (gmail), no developer name, no business domain — low identity accountability.
- No CSP declared (MV3 mitigates somewhat, but no_developer_name + gmail + broad permissions raises residual concern).
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://jointoucan.com/partners/volumebooster (affiliate/monetization redirect).
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- broad_host_permissions manifest http://*/*, https://*/*, and <all_urls> all declared simultaneously — redundant and maximally broad.
- free_webmail_dev_no_name store Developer email alexanderkcheng@gmail.com, developer_name empty; no business domain identity.
- verified_publisher_featured store Both verified_publisher=true and is_featured_by_google=true; discounts applied but capped due to monetization signal.
- js_external_host crx jointoucan.com referenced as external JS host — same domain as affiliate uninstall URL.
- no_csp manifest content_security_policy is null; csp_present=false on MV3 extension.
- tab_capture_all_urls manifest tabCapture + <all_urls> content_scripts enables audio capture on every site user visits.
Permissions Breakdown
- tabCapture high Can capture audio/video from any tab — core function but high capability.
- activeTab medium Access to currently active tab content on user interaction.
- offscreen low Offscreen document for audio processing; low standalone risk.
- storage low Stores extension settings locally.
- unlimitedStorage low No storage quota; low direct risk.
- windows low Window enumeration; low risk.
- http://*/* high Broad host access to all HTTP sites.
- https://*/* high Broad host access to all HTTPS sites.
- <all_urls> high Catch-all host permission — redundant triple coverage amplifies risk.
Pillar Scores
Permissions7.00
Reputation4.50
Network2.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:17
Listing SHA
7f17ddeef085…
Force block
— not fired
Score recovered
no
Elapsed
—