Meta Ads Data Advisor
fdgfkebogiimcoedlicjlajpkdmockpc
Risk Score
3.96
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- debugger + cookies + <all_urls> combo gives full runtime control and cookie access on every site
- brand_mention.is_impersonation=true for 'meta' but verified_publisher=false — unverified Meta branding
- Privacy policy is Facebook's generic corporate policy; scope_extension=false means THIS extension's data practices undisclosed
- No CSP (csp_present=false) with innerHTML sinks in bundled React vendor — DOM-XSS risk on extension pages
- install_url_hijack=true: onInstalled opens a third-party URL
Evidence
- high_perm_combo manifest debugger + cookies + webRequest + scripting + <all_urls>: full-page observation and runtime control on every site.
- brand_impersonation store brand_mention.is_impersonation=true for 'meta'; developer not verified_publisher nor is_featured_by_google=true resolves discount.
- privacy_policy_not_scoped api Policy is facebook.com corporate page; scope_extension=false, data_collection=false — generic, not extension-specific.
- no_csp manifest content_security_policy=null on MV3 extension with innerHTML sinks in React vendor bundle.
- install_url_hijack crx install_url_hijack=true; target URL not captured but onInstalled opens external page.
- dom_xss_sink crx Two dom_sink_innerhtml_userctrl findings in react-vendor bundle; no CSP amplifies risk.
- looks_throwaway_domain api threat_intel developer_domain fb.com flagged looks_throwaway=true despite being a known Meta domain.
- webstore_install_count store 3,000,000 installs — high blast radius if extension is compromised or mis-attributed.
Permissions Breakdown
- storage low Local state persistence; low standalone risk.
- scripting high Injects scripts into pages; paired with <all_urls> is high impact.
- tabs medium Can read tab URLs and titles across all open tabs.
- activeTab low Transient access to active tab only; less risky alone.
- unlimitedStorage low Allows large local data accumulation; low direct risk.
- webNavigation medium Monitors navigation events across all pages.
- cookies high Combined with <all_urls>: can read/write cookies on any domain. ×1.2 multiplier.
- webRequest high Can observe all HTTP requests on every site visited.
- alarms low Background scheduling only; minimal standalone risk.
- debugger high Full JS runtime control, network interception, breakpoints on any tab.
- tabGroups low Tab grouping UI only; low risk.
- identity low OAuth token acquisition; no scopes declared reduces risk.
- sidePanel low UI surface only; low standalone risk.
- <all_urls> high Broad host access enabling content scripts and API calls on every site.
Pillar Scores
Permissions8.50
Reputation5.50
Network2.50
Webstore4.50
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| sssiednaf383673dp727562726963xsx | 5.76 | Medium | review | 2026-09-07 |
| sssieddrubricxsx | 4.33 | Medium | review | 2026-08-02 |
| %76%33%2E%36%39%36%38%39%22%28%29%3B%7D%5D%39%31%37%31 | 4.18 | Medium | review | 2026-07-29 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 3.96 | Low | review | 2026-07-29 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 3.02 | Low | review | 2026-07-29 |
| dfb__${98991*97996}__::.x | 5.23 | Medium | review | 2026-07-29 |
| dfb{{98991*97996}}xca | 4.57 | Medium | review | 2026-07-29 |
| v3.6'"()&%<zzz><ScRiPt >eXGc(9585)</ScRiPt> | 4.09 | Medium | review | 2026-07-29 |
| v3.6&n982464=v950785 | 4.29 | Medium | review | 2026-07-29 |
| v3.6 | 3.96 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA
27ed64b7edfa…
Force block
— not fired
Score recovered
no
Elapsed
29.1s