DAT GO
fjpobenajidogfpilgbjgbglcanfjnoa
Risk Score
6.32
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- CRITICAL permission stack: proxy+webRequest+cookies+scripting+management all with <all_urls> — full browser traffic interception capability.
- management permission allows disabling/uninstalling other security extensions without user awareness.
- Host permissions extend to *://*.google.com/* and script.google.com with no stated justification.
- No CSP (MV3 default applies but no explicit policy), combined with external hosts including apexskillzone.com backend.
Evidence
- proxy+webRequest+<all_urls> manifest proxy and webRequest with <all_urls> enables full MITM of browser traffic.
- management permission manifest Can enumerate and disable other installed extensions; high abuse potential.
- google.com host access manifest *://*.google.com/* host permission unjustified for DAT session management tool.
- external backend hosts crx JS contacts datbackend.apexskillzone.com and datbackup.apexskillzone.com — third-party unknown domains.
- install_perm_anomaly api 98 installs with proxy+management+webRequest+cookies+scripting = small_install_high_perm true.
- install_url_hijack manifest onInstalled opens https://dat.com — minor but noted redirect pattern.
- privacy policy adequate api Policy scoped, discloses collection/retention/third-party sharing; passes Privacy pillar.
- no bad hosts / no CVEs api threat_intel bad_host_hits empty; cve_findings_raw empty; code_findings_raw empty.
Permissions Breakdown
- cookies high Can read/write cookies across all URLs; paired with <all_urls> is critical.
- storage low Local extension storage; low standalone risk.
- tabs medium Access to tab URLs and metadata across browser.
- scripting high Can inject JS into any page via <all_urls> host permission.
- management high Can enumerate, disable, or uninstall other extensions.
- proxy high Can redirect all browser traffic through attacker-controlled proxy.
- webRequest high Can observe and intercept all HTTP requests across all URLs.
- webRequestAuthProvider high Can supply credentials for proxy/server auth challenges.
- declarativeNetRequest medium Can block/redirect network requests declaratively.
- <all_urls> high Broad host access amplifies cookies, scripting, webRequest to full browser scope.
- *://*.dat.com/* low Scoped to primary service domain; expected for DAT session management.
- *://script.google.com/* high Access to Google Apps Script execution endpoints is unusual for a DAT session tool.
- *://*.google.com/* high Broad Google domain access including account pages; not justified by stated function.
Pillar Scores
Permissions9.50
Reputation6.00
Network7.50
Webstore5.50
Maintenance0.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:04
Listing SHA
8e7c3f2fec23…
Force block
— not fired
Score recovered
no
Elapsed
—