fpfipmndcbfnofbedjokcjlfogdpmcop
fpfipmndcbfnofbedjokcjlfogdpmcop
Risk Score
8.12
Risk Level:
Critical
Recommendation:
🚫 BLOCK
Category DeveloperTools
Installs —
Rating —
Last updated
—
Manifest version MV?
CSP present ❌ no
Developer —
Verified publisher
❌ no
Featured by Google
❌ no
Web Store
open ↗
Top Risks
- Abandoned MV2 extension (59 months stale) with maximum-privilege stack: debugger+proxy+webRequest+nativeMessaging+<all_urls>.
- nativeMessaging to unrecognized companion app creates arbitrary code execution path to host OS.
- eval_user_input and function_constructor in content/popup scripts allow dynamic code execution across all sites.
- cookies+<all_urls>+webRequestBlocking enables full session hijack and traffic manipulation on any site.
- Privacy policy not scoped to this extension; third-party silence unresolved; no retention disclosure.
Evidence
- maintenance_critical store Last updated Sep 2021; 59 months stale. MV2 extension past Chrome deprecation window.
- high_perm_stack manifest debugger+proxy+webRequest+webRequestBlocking+nativeMessaging+cookies+<all_urls> — maximum capability surface.
- native_messaging_unrecognized crx nativeMessaging present, publisher_recognized=false. Unvetted native app bridge adds OS-level risk.
- eval_findings crx function_constructor in content_script.js and eval_user_input in popup.js — dynamic code execution confirmed.
- unsafe_eval_csp manifest CSP allows 'unsafe-eval' on script-src, amplifying eval risk.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() set; target null but hook present.
- privacy_policy_inadequate api Policy fetched but scope_extension=false, data_collection=false, retention=false, third_party_silence=true.
- small_install_high_perm store Only 422 installs with maximum-tier permissions; tail attack surface anomaly flagged.
Permissions Breakdown
- bookmarks medium Access to full bookmark tree; medium sensitivity.
- clipboardRead medium Reads clipboard; can capture sensitive copied data.
- clipboardWrite medium Writes clipboard; can inject data into user workflow.
- cookies high Full cookie access across all sites paired with <all_urls>; ×1.2 amplifier applies.
- debugger high Can attach debugger to any tab, intercept/modify traffic, capture credentials.
- downloads medium Can initiate and manage downloads silently.
- downloads.shelf low UI control only; low standalone risk.
- notifications low System notifications; minor risk.
- storage low Local extension storage; low risk.
- tabs medium Can enumerate all open tabs and their URLs.
- proxy high Can reroute all browser traffic through arbitrary proxy.
- webRequest high Intercept and inspect all HTTP requests across all URLs.
- webRequestBlocking high Modify or block any HTTP request; combined with <all_urls> is maximum-risk.
- nativeMessaging high Bridge to unrecognized native app; publisher_recognized=false adds +3.0.
- contextMenus low Adds context menu items; low standalone risk.
- <all_urls> high Content scripts injected into every site; broadest possible host access.
Pillar Scores
Permissions10.00
Reputation4.00
Network6.00
Webstore5.50
Maintenance10.00
Privacy9.00
Code Quality7.50
CVE Exposure0.00
Scoring History
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 7.69 | High | block | 2026-08-05 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 6.86 | High | block | 2026-08-05 |
| v3.6&n971973=v961763 | 8.16 | Critical | block | 2026-08-05 |
| v3.6 | 8.12 | Critical | block | 2026-08-03 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-03 07:21
Listing SHA
f95ecbefe710…
Force block
— not fired
Score recovered
no
Elapsed
—