Popup Blocker (Lite)
flkpkonhokophabdnmggfbdlbdknebel
Risk Score
5.02
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — does not scope to this extension, yet admits data collection and third-party sharing (+10.0 Privacy).
- Free-webmail developer (gmail.com) with no verified business identity elevates accountability risk.
- install_url_hijack and uninstall_url_hijack both flagged; targets null but the hooks exist (+2.0 each Webstore).
- webRequest + scripting + <all_urls> with no CSP gives broad capability over every page visited.
- Single external JS host (webbrowsertools.com) with no publisher verification or CSP constraint.
Evidence
- privacy_policy_generic store PP is Google account policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5-D).
- free_webmail_developer manifest Developer email jorvi.uuer@gmail.com; no business domain; no verified publisher. Reputation start 5.0 +1.5.
- install_uninstall_url_hijack crx install_url_hijack=true, uninstall_url_hijack=true; targets null but hooks present; +2.0 each Webstore per rubric.
- broad_host_plus_webRequest_scripting manifest <all_urls> paired with webRequest and scripting; justified-broad discount applies for Adblock category (-1.5 Permissions).
- no_csp_mv3 manifest content_security_policy=null; MV3 so no +2.0 network penalty, but dom_sink risk context elevated.
- external_js_host crx js_external_hosts=[webbrowsertools.com]; 1 distinct domain; no bad-host or affiliate hit confirmed.
- cve_clean api cve_findings_raw=[]; no CVE exposure; CVE pillar=0.0.
- code_findings_clean crx code_findings_raw=[]; obfuscation_score=0.0; no malicious code patterns detected.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata; medium risk paired with broad host access.
- storage low Stores extension settings locally; low standalone risk.
- scripting high Allows programmatic script injection into pages; high risk with <all_urls>.
- webRequest high Can observe all network requests across all URLs; high surveillance capability.
- notifications low Can display notifications; low risk in isolation.
- <all_urls> (host_permission) high Broad host access enables content scripts and scripting on every site.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.00
Webstore5.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA
09c483b0d721…
Force block
— not fired
Score recovered
no
Elapsed
23.6s