Directo - Travel Deals - Save on Hotels
fonalplhodhnenmokepaijoemaednpjm
Risk Score
3.22
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- webRequest + broad host access (<all_urls>) enables observation of all user HTTP traffic across every site.
- scripting + broad host access allows arbitrary JS injection into any page the user visits.
- new Function() constructor in background.js and options.js; dynamic code execution risk.
- No developer name listed; identity accountability gap for a 300K-install extension.
- identity.email grants access to signed-in Google account email; PII collection risk.
Evidence
- broad_host_permissions manifest host_permissions includes http://*/* and https://*/* — all sites reachable.
- webRequest_broad manifest webRequest permission paired with <all_urls> enables full request interception.
- function_constructor_background crx new Function() in js/background.js — dynamic code execution in privileged service worker context.
- dom_sink crx innerHTML assigned from variable in js/vendor.js; DOM-XSS sink present.
- no_developer_name store developer_name is empty string; no 'Offered by' identity for a 300K-install extension.
- featured_by_google store is_featured_by_google=true provides partial trust signal but no verified publisher badge.
- monetization_telemetry crx google-analytics.com in js_external_hosts; classified as telemetry only, low tier.
- privacy_policy_adequate api Policy fetched, scoped to extension, discloses data collection, retention, and third-party sharing.
Permissions Breakdown
- storage low Standard local data persistence; low risk.
- unlimitedStorage low Extends storage quota; minimal direct risk.
- webRequest high Can observe all HTTP requests across all sites — high surveillance capability.
- identity medium Access to Chrome identity API; can initiate OAuth flows.
- identity.email medium Reads the signed-in Google account email; user PII.
- activeTab low Scoped to user-activated tab; limited reach alone.
- scripting medium Programmatic script injection into pages; high impact with broad host access.
- alarms low Background scheduling only; low direct risk.
- http://*/* high Broad host access over all HTTP sites — amplifies webRequest and scripting.
- https://*/* high Broad host access over all HTTPS sites — amplifies webRequest and scripting.
Pillar Scores
Permissions7.50
Reputation4.50
Network2.00
Webstore2.50
Maintenance0.00
Privacy0.00
Code Quality3.50
CVE Exposure0.00
Scoring History
| sssiedn4300fd82dp727562726963xsx | 4.15 | Medium | review | 2026-09-07 |
| v3.6 | 3.22 | Low | review | 2026-07-21 |
Bookkeeping
Rubric v3.6
Scored at 2026-07-21 03:41
Listing SHA
792598129ffc…
Force block
— not fired
Score recovered
no
Elapsed
—