AutoBuy Flash Sales, Deals, and Coupons
gbnahglfafmhaehbdmjedfhdmimjcbed
Risk Score
4.76
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own account policy — not scoped to this extension; admits data collection and third-party sharing.
- Content script injected on all URLs (<all_urls>) from a free-webmail developer with no named developer entity.
- Extension contacts getmatchingcouponsanddeals.info — an unverified third-party domain with no threat-intel clearance.
- Developer email is free webmail (gmail) with no developer name or business identity disclosed.
- MV3 + no CSP: missing content_security_policy reduces in-extension sandbox assurance.
Evidence
- host_permissions <all_urls> + content_scripts_matches <all_urls> manifest Extension has unrestricted host access and injects content scripts on every page visited.
- Privacy policy is Google Account policy (not extension-scoped) store privacy_policy_classification: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (D rule).
- Free-webmail developer, no developer name store developer_email=autobuyapp@gmail.com, developer_name empty; free-webmail + no business identity → elevated reputation risk.
- External JS host: getmatchingcouponsanddeals.info crx Extension contacts unverified third-party domain; not in threat-intel bad list but unverifiable.
- No CSP declared (csp_present=false, MV3) manifest MV3 has strict default but no explicit CSP; reduces defence-in-depth for content scripts.
- Verified publisher badge present store verified_publisher=true; applies -3.0 to reputation base, but free-webmail floor applies.
- months_since_update=6 store 3–6 months stale → +1.5 maintenance score.
- code_findings_raw empty, obfuscation_score=0.0 crx No suspicious code patterns detected; code quality pillar = 0.0.
Permissions Breakdown
- storage low Stores local extension state; low risk in isolation.
- tabs medium Can read tab URLs and titles across all open tabs.
- background low Keeps service worker active; enables persistent background operation.
- <all_urls> (host_permissions) high Grants content-script and fetch access to every site; broad capability for a shopping helper.
- <all_urls> (content_scripts_matches) high Content script injected into every page; can read/modify any page content.
Pillar Scores
Permissions5.50
Reputation6.00
Network2.00
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:45
Listing SHA
031bda81a55e…
Force block
— not fired
Score recovered
no
Elapsed
—