VnChatGPT
fkfilegpkbdejgolppocomljgjmfllim
Risk Score
4.44
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Search provider override sets vnchatgpt.com as default engine, routing all user queries through an unverified operator.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- No developer identity (name, email, domain) — zero accountability; anonymous publisher.
- No update date or install count available — extension provenance entirely unverifiable.
- AI-branded extension with search override: high potential for query harvesting and monetization without disclosure.
Evidence
- search_provider_override manifest chrome_settings_overrides sets VnChatGPT as default search engine; all queries routed to vnchatgpt.com.
- generic_google_privacy_policy store Privacy policy URL is Google account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
- no_developer_identity store developer_name and developer_email both empty; no verified publisher; no 'Offered by' info.
- missing_store_metadata store installs, rating, last_updated all null — cannot assess reach or maintenance.
- content_script_narrow manifest content_scripts limited to https://*.vnchatgpt.com/* — operator's own domain only.
- no_cve_findings crx cve_findings_raw empty; no CVE exposure detected.
- no_bad_hosts crx threat_intel.bad_host_hits and monetization_hits empty; js_external_hosts empty.
- obfuscation_clean crx obfuscation_score=0.0; code_findings_raw empty; 1 JS file scanned with no findings.
Permissions Breakdown
- chrome_settings_overrides.search_provider (is_default=true) medium Overrides default search engine to vnchatgpt.com; high-impact UX change, routes all searches through operator.
- content_scripts on https://*.vnchatgpt.com/* low Narrow host scope limited to operator's own domain; low lateral reach.
Pillar Scores
Permissions3.00
Reputation7.50
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 16:08
Listing SHA
60cbe98c595a…
Force block
— not fired
Score recovered
no
Elapsed
—