BeLikeNative – AI Writing Assistant | Paraphrase, Rewrite & Translate Text
gchojmpfpbpmpfgdppfdkpchikbcgabp
Risk Score
5.22
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true → generic policy admitting 3rd-party data sharing (Privacy=10.0).
- content_scripts on <all_urls> gives broad read/write access to all page content including sensitive data on every site.
- Dynamic script creation (script_src_dynamic) + new Function() constructor with no CSP — remote code injection risk.
- innerHTML sink (dom_sink_innerhtml_userctrl) with no CSP present amplifies DOM-XSS risk.
- No developer name listed; AI extension processing page content with unscoped privacy policy.
Evidence
- privacy_policy_generic_admits_sharing api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 per v3.5 rule D.
- content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] gives full page-content access on every site.
- code_findings_script_src_dynamic_and_function_constructor crx script_src_dynamic + function_constructor in sidepanel.js; no CSP to constrain.
- dom_sink_innerhtml_no_csp crx dom_sink_innerhtml_userctrl in vendor.js; csp_present=false amplifies to +2.0.
- no_csp_mv3 manifest content_security_policy=null; MV3 has strict default but dynamic script creation bypasses it.
- install_url_hijack store install_url_hijack=true targeting welcome.html; onInstalled opens a page.
- ai_extension_page_content store AI writing assistant with <all_urls> content script processes arbitrary page text.
- verified_publisher store verified_publisher=true; discount capped to -1.0 due to monetization/privacy policy concern per v3.5 rule E.
Permissions Breakdown
- alarms low Schedules background tasks; minimal data risk.
- contextMenus low Adds right-click menu items; low risk alone.
- notifications low Show desktop notifications; low risk.
- sidePanel low Opens side panel UI; low risk.
- storage low Local storage access; low risk.
- content_scripts:<all_urls> high Content script runs on every site; can read/modify all page content.
- host_permissions:https://backend.belikenative.com/* low Scoped to own backend; narrow exfil surface.
Pillar Scores
Permissions3.50
Reputation4.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality6.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA
6943e786c694…
Force block
— not fired
Score recovered
no
Elapsed
29.3s