Note Sidebar
emiochiflnnegkecnjndifbobmbepdne
Risk Score
2.25
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- install_url_hijack on install opens https://x.com/intent/tweet — unsolicited third-party redirect.
- innerHTML assigned from user-controlled variable in panel.js and pip.js — DOM-XSS sink.
- Operator cluster has 1 sibling extension under same developer fingerprint.
- No developer display name listed in store; identity relies solely on email/domain.
- CSP img-src includes wildcard '*' allowing arbitrary image origins.
Evidence
- install_url_hijack crx onInstalled opens https://x.com/intent/tweet?text= — third-party URL redirect on install.
- dom_sink_innerhtml_userctrl crx scripts/panel.js and pip.js assign noteValue to innerHTML — DOM-XSS risk if note content is attacker-influenced.
- verified_publisher store Developer is verified publisher; domain stefanvd.net resolves and is not throwaway.
- operator_cluster_sibling api sibling_count=1 under compound fingerprint; low cluster size.
- csp_img_wildcard crx CSP img-src includes '*' — allows images from any origin, minor info-leak vector.
- privacy_policy_third_party store Privacy policy confirms data collection, retention, and third-party sharing; scoped to extension.
- no_cve_findings crx cve_findings_raw is empty; no known vulnerable libraries detected.
- no_bad_hosts crx threat_intel bad_host_hits, affiliate_hits, and monetization_hits all empty.
Permissions Breakdown
- contextMenus low Adds right-click menu items; minimal risk.
- storage low Local data persistence; standard for note apps.
- sidePanel low Opens Chrome side panel UI; no data exfil risk.
- unlimitedStorage low Removes storage quota; expected for note app.
- scripting medium Can inject scripts into tabs; combined with activeTab limits scope.
- activeTab medium Access current tab on user action; scoped but grants tab content access.
Pillar Scores
Permissions2.30
Reputation3.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Operator Siblings (1)
Other extensions sharing this developer's compound fingerprint:
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA
48e2c15d9117…
Force block
— not fired
Score recovered
no
Elapsed
22.7s