YT Zoom
gaanolhdjafoofiogciikoimdfakndjp
Risk Score
5.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: mentions 'YouTube' and 'Zoom' — is_impersonation=true, not a verified publisher.
- Privacy policy is Google's generic account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — worst-case privacy score.
- Extension not updated in 46 months (>36mo); abandoned and maintenance score maxed.
- Developer email is free Gmail with no verifiable business identity.
- Featured badge partially mitigates reputation but does not override impersonation or privacy failures.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands ['youtube','zoom'] mentioned; developer_domain is gmail.com, not verified owner.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 per v3.5 rule D.
- maintenance_abandoned store Last updated August 2022, 46 months ago (>36mo). Maintenance pillar = 10.0.
- free_webmail_developer store Developer email cholodymedia@gmail.com; free webmail, no business website verifiable.
- featured_by_google store is_featured_by_google=true; provides -2.0 reputation discount (featured badge).
- no_csp manifest content_security_policy is null; MV3 so no +2.0 network penalty, but CSP absent.
- content_scripts_scoped manifest content_scripts_matches=['https://www.youtube.com/*']; narrow scope matching stated function.
- cve_none crx cve_findings_raw=[]; no CVE exposure detected.
Permissions Breakdown
- content_scripts:https://www.youtube.com/* medium Injects script into YouTube pages; scoped to single domain, consistent with stated function.
Pillar Scores
Permissions1.00
Reputation7.50
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA
23f6a2d2fbcf…
Force block
— not fired
Score recovered
no
Elapsed
19.1s