Canvas Blocker & Fingerprint Protect
gbkicngmnoedeajgodbbokjadbfbbpng
Risk Score
2.88
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Free-webmail dev (binderpo343@gmail.com) with generic name 'ChromeExtensions' — low accountability.
- Content scripts run on <all_urls> giving broad reach despite minimal declared permissions.
- Privacy policy hosted on free Google Sites; lacks data retention disclosure.
- Description claims ad-blocking but lacks declarativeNetRequest/webRequest — promise/permission mismatch.
- Very low install count (147) with no ratings — no community vetting signal.
Evidence
- developer_email_free_webmail store Dev email binderpo343@gmail.com with generic name 'ChromeExtensions'; no verified business identity.
- content_scripts_all_urls manifest content_scripts_matches includes <all_urls>; JS injected on every page visited.
- privacy_policy_free_hosting_no_retention api Policy on sites.google.com; scope_extension=true, data_collection=true, retention=false.
- description_promise_mismatch store Description promises ad-blocking but no declarativeNetRequest or webRequest permission present.
- no_ratings_low_installs store 147 installs, 0 ratings — no community trust signal available.
- third_party_silence api Privacy policy does not address third-party data sharing despite data_collection=true.
- no_code_findings crx 0 code findings, obfuscation_score=0.0, no external JS hosts — clean static scan.
- no_bad_host_hits api threat_intel shows no bad hosts, monetization hits, or affiliate hits.
Permissions Breakdown
- storage low Stores extension settings locally; no cross-origin data access.
- content_scripts <all_urls> medium Injects JS on every site; broad reach even without host_permissions API access.
Pillar Scores
Permissions1.30
Reputation7.00
Network0.00
Webstore4.00
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 15:53
Listing SHA
5cafdcbd1ba5…
Force block
— not fired
Score recovered
no
Elapsed
—