Annotate pdf
ffkgggpfimdabhlfomcfhpgbmjfdbhfh
Risk Score
4.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; data collection and 3rd-party sharing admitted.
- <all_urls> host_permissions + scripting allows code injection on every site the user visits.
- Dynamic script creation (script_src_dynamic) in bundled JS can load remote code at runtime.
- Content script injected into Google Search (beyond PDF scope) — unexplained scope expansion.
- install_url_hijack and uninstall_url_hijack flags set; no target URL captured but pattern is concerning.
Evidence
- privacy_policy_generic store PP URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection+3rd_party_sharing=true → +10.0 privacy.
- script_src_dynamic crx Two JS chunks create dynamic <script> elements — runtime script loading risk.
- host_permissions_all_urls manifest <all_urls> combined with scripting permission = high-capability injection surface.
- content_script_scope_mismatch manifest content_scripts include https://www.google.com/search* — not justified by PDF annotation category.
- install_uninstall_url_hijack store install_url_hijack=true and uninstall_url_hijack=true; targets null but flags raised.
- external_hosts crx 6 external JS hosts: fonts.googleapis.com, fonts.gstatic.com, nextjs.org, pdfedit.ai, reactjs.org, use.typekit.net.
- developer_name_missing store developer_name is empty string; reputation penalized; verified_publisher=true applies floor.
- maintenance_stale store months_since_update=15 (6-12mo band exceeded); 12-24mo band → +6.0 maintenance pillar.
Permissions Breakdown
- scripting medium Can inject scripts into pages; paired with <all_urls> host permission, elevates risk significantly.
- contextMenus low Adds right-click menu items; low standalone risk.
- <all_urls> (host_permissions) high Broad host access across all URLs; combined with scripting creates high-capability surface.
- content_scripts: http://*/*.pdf, https://*/*.pdf medium Scoped to PDF files — reasonable for stated function, but also injects into Google Search.
- content_scripts: https://www.google.com/search* medium Injecting into Google Search results goes beyond PDF annotation scope.
Pillar Scores
Permissions5.50
Reputation3.50
Network3.50
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA
5bd875dd15d0…
Force block
— not fired
Score recovered
no
Elapsed
36.1s