All Netflix Categories
fkjmbiakdlohkehbmcoalflelnbhpkpl
Risk Score
5.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetch failed — treated as unfetched; privacy score maxes out at 10.0.
- Brand impersonation: extension title/description prominently references Netflix without confirmed ownership.
- 25 months since last update — stale, approaching triple-stale threshold.
- DOM-XSS sink (innerHTML with user-controlled variable) found in popup.js.
- Developer name absent from listing; identity relies solely on simkl.com email.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['netflix']; confirmed_owner=false.
- privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError); scored as +10.0.
- maintenance_stale store months_since_update=25; >24mo band +8.5; installs 20k <10k zombie threshold not met.
- dom_xss_sink crx js/popup.js: innerHTML assigned from variable; CSP present so base +0.5 not amplified.
- no_developer_name store developer_name is empty string; +1.0 reputation penalty applied.
- cve_none crx cve_findings_raw=[]; jquery 3.7.1 bundled with no known CVEs; CVE pillar=0.0.
- network_clean crx bad_host_hits=[], monetization_hits=[], affiliate_hits=[]; js_external_hosts limited to simkl.com and www.netflix.com.
- operator_cluster_singleton api sibling_count=0; no cluster risk.
Permissions Breakdown
- storage low Stores local preferences; no cross-origin or sensitive data access.
Pillar Scores
Permissions0.30
Reputation7.00
Network0.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality0.50
CVE Exposure0.00
Scoring History
| sssiedn2a2a445adp727562726963xsx | 5.36 | Medium | review | 2026-08-27 |
| v3.6 | 5.08 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA
cb97502c5585…
Force block
— not fired
Score recovered
no
Elapsed
19.2s