YT Search Helper
ekfbpedkallblckjgijmibabfcacgjhl
Risk Score
4.36
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Gmail dev email (sixtythirdholding@gmail.com) with no business identity — unverified, unaccountable developer.
- Privacy policy is Google's own account policy — not scoped to this extension; data_collection and third_party_sharing both true under that policy.
- YouTube brand mention confirmed impersonation flag (confirmed_owner=false) — could mislead users about affiliation.
- External host www.ykapf.com of unknown purpose listed in js_external_hosts — unexplained third-party endpoint.
- Only 8 installs with no ratings — no community signal; high tail-attack-surface uncertainty.
Evidence
- free_webmail_dev store Developer email sixtythirdholding@gmail.com is a Gmail address with no verified business presence.
- brand_impersonation store brand_mention.is_impersonation=true for 'youtube'; developer is not confirmed owner.
- generic_privacy_policy store Privacy URL is Google's account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — v3.5 D: +10.0.
- unknown_external_host crx js_external_hosts includes www.ykapf.com — unknown domain, no threat-intel match but unexplained.
- no_csp manifest content_security_policy is null (MV3 default strict applies, no explicit CSP override needed — no MV2 penalty).
- very_low_installs store Only 8 installs and 0 ratings — minimal community validation, high uncertainty.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false — no trust signals from Google.
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, no CVEs — code surface appears benign.
Permissions Breakdown
- storage low Stores extension settings locally; no user data exfil risk on its own.
- https://www.youtube.com/* medium Host permission scoped to YouTube only; allows content script read/write on all YouTube pages.
- https://m.youtube.com/* medium Same as desktop YouTube host — mobile YouTube pages also fully accessible.
Pillar Scores
Permissions1.30
Reputation8.50
Network0.00
Webstore4.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:55
Listing SHA
c6c558baa587…
Force block
— not fired
Score recovered
no
Elapsed
—