eoolfmmapnkhandljfaaofncecfakljd
eoolfmmapnkhandljfaaofncecfakljd
Risk Score
4.43
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Content script on all URLs combined with no CSP; 4 innerHTML DOM-XSS sinks across injection files.
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- No developer identity (no name, no email, no verified publisher); extension cannot be attributed.
- Contacts gsg-extension.com and pepper.com endpoints whose ownership is unverifiable given missing developer info.
- Maintenance data entirely missing; update cadence and lifecycle accountability unknown.
Evidence
- content_scripts_broad manifest content_scripts_matches covers http://*/* and https://*/* — full browse-history injection surface.
- no_csp manifest csp_present=false on MV3 extension; no Content-Security-Policy declared despite broad content scripts.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- no_developer_identity store developer_name, developer_email, and title all empty; no attribution possible.
- dom_xss_sinks crx 4 innerHTML-from-variable sinks in injection-root.js, injection-serp.js, settings.js, window.js; no CSP mitigates.
- external_hosts crx 12 external JS hosts including caa-configurations.gsg-extension.com, ocular-xtn.pepper.com, logs.browser-intake-datadoghq.eu.
- maintenance_unknown store last_updated and months_since_update are null; no update history available.
- manifest_name_unresolved manifest manifest_name is __MSG__extensionName__; localized name not resolved, title field empty in listing.
Permissions Breakdown
- alarms low Schedules periodic tasks; low risk alone.
- storage low Stores extension preferences locally.
- tabs medium Can read tab URLs and titles; moderate privacy surface.
- unlimitedStorage low Allows large local data; no exfil risk by itself.
- content_scripts http://*/* https://*/* high Injects JS into every page; broad capability even without declared host_permissions.
Pillar Scores
Permissions3.30
Reputation7.00
Network3.50
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-06 05:33
Listing SHA
01439e6c32fd…
Force block
— not fired
Score recovered
no
Elapsed
—