FlipHTML5 | AnyFlip Downloader & Converter to PDF, EPUB & DOCX
fejalehlkcncbmmaeljpnjdffjjkildd
Risk Score
4.11
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Free-webmail developer (gmail) with no developer name and privacy policy on unrelated domain ext-boost.com.
- Broad https://*/* host permission grants access to all HTTPS sites, far beyond anyflip/fliphtml5 targets.
- identity.email permission harvests Google account email; no justification for a document downloader.
- No CSP declared (MV3 default, but no explicit policy) + innerHTML sink in popup.js raises DOM-XSS risk.
- Description promises download functionality but lacks 'downloads' permission — capability mismatch signal.
Evidence
- free_webmail_dev_no_name store Developer email is exportmyinfohq@gmail.com with no developer_name; elevated identity-risk per rubric.
- broad_host_permission manifest host_permissions includes https://*/* despite content_scripts scoped only to anyflip.com/fliphtml5.com.
- identity_email_permission manifest identity.email declared; unnecessary for a PDF/EPUB converter — collects Google account email.
- privacy_policy_third_party_sharing api Policy on ext-boost.com discloses data collection and third-party sharing but omits retention details.
- dom_xss_sink crx innerHTML used with variable input in popup.100f6462.js; no CSP to mitigate DOM-XSS.
- description_promise_mismatch store Extension promises download capability but lacks the 'downloads' permission in manifest.
- low_rating store Rating 2.4 — below 3.0 threshold; indicates user dissatisfaction.
- external_host_api_ext_api_com crx js_external_hosts includes api.ext-api.com — unrelated third-party API endpoint for a document downloader.
Permissions Breakdown
- storage low Stores local extension state; limited blast radius.
- identity medium OAuth token access; can fingerprint signed-in Google account.
- identity.email medium Exposes user's Google email address to extension.
- tabs medium Can read tab URLs and titles across all open tabs.
- activeTab low Scoped to user-activated tab; lower risk than broad host access.
- https://*/* high Broad host permission covering all HTTPS sites; high reach.
Pillar Scores
Permissions5.50
Reputation6.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 16:09
Listing SHA
fe48d67f33ae…
Force block
— not fired
Score recovered
no
Elapsed
—