ghgabhipcejejjmhhchfonmamedcbeod
ghgabhipcejejjmhhchfonmamedcbeod
Risk Score
3.68
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Category PrivacyTool
Installs —
Rating —
Last updated
—
Manifest version MV?
CSP present ❌ no
Developer —
Verified publisher
❌ no
Featured by Google
❌ no
Web Store
open ↗
Top Risks
- Broad host access (http/https all URLs) combined with cookies and browsingData enables full session and history access.
- Uninstall URL hijack detected; redirects user after removal to a third-party destination.
- Privacy policy confirms data collection and third-party sharing but lacks retention disclosure.
- last_updated unknown — maintenance risk cannot be fully assessed; 6+ months stale assumed.
- CSP connect-src includes api64.com and appn.center (non-dev domains); adds external trust surface.
Evidence
- broad_host_permissions manifest host_permissions include http://*/* and https://*/* paired with cookies and browsingData.
- uninstall_url_hijack crx uninstall_url_hijack=true; target unspecified but triggers post-removal redirect.
- verified_publisher_featured store Extension has verified publisher badge and is featured by Google; strong trust signal.
- privacy_policy_third_party_sharing api Policy fetched: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- external_csp_hosts manifest CSP connect-src includes api64.com and appn.center outside developer-controlled domain.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; no malicious code indicators detected.
- maintenance_unknown store last_updated is null; cannot confirm recency — defaulting to 6-12 months stale band.
- operator_cluster_dev_email api sibling_count=0 compound; dev_email dimension shows 2 — one sibling extension under same email.
Permissions Breakdown
- tabs medium Access to tab URLs and metadata; moderate risk for a privacy-cleaning tool.
- browsingData high Can delete history, cookies, cache across all sites; core function but powerful.
- history high Full read/write access to browsing history; broad data access.
- cookies high Read/delete cookies across all origins; paired with broad host access.
- scripting medium Can inject scripts; scope limited by host_permissions.
- storage low Local extension storage; standard and low risk.
- contextMenus low Adds right-click menu items; minimal risk.
- http://*/* high Broad host access over HTTP; combined with cookies amplifies risk.
- https://*/* high Broad host access over HTTPS; combined with cookies amplifies risk.
Pillar Scores
Permissions4.50
Reputation2.00
Network3.50
Webstore4.00
Maintenance6.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.14 | Low | review | 2026-08-09 |
| "fsssiedxasssiedx | 3.09 | Low | review | 2026-08-09 |
| 'fsssiedxasssiedx | 3.17 | Low | review | 2026-08-09 |
| 'fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.04 | Low | review | 2026-08-09 |
| "fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.54 | Low | review | 2026-08-09 |
| fsssiedxa<sssiedx | 3.05 | Low | review | 2026-08-09 |
| v3.69490"();}]9524 | 3.57 | Low | review | 2026-08-05 |
| dfb{{98991*97996}}xca | 2.91 | Low | review | 2026-08-05 |
| v3.6&n993967=v939252 | 2.18 | Low | review | 2026-08-05 |
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%71%56%76%45%28%39%38%34%34%34%29%22 | 4.04 | Medium | review | 2026-08-04 |
| <th:t="${dfb}#foreach | 3.40 | Low | review | 2026-08-04 |
| v3.6&n913079=v980432 | 3.29 | Low | review | 2026-08-04 |
| fsssiedxa"sssiedx | 3.02 | Low | review | 2026-08-03 |
| fsssiedxa | 2.82 | Low | review | 2026-08-03 |
| sssieddrubricxsx | 3.01 | Low | review | 2026-08-03 |
| v3.6</script><script>7AjZ(9425)</script> | 2.92 | Low | review | 2026-07-29 |
| %F6"onmouseover=7AjZ(94585)// | 3.48 | Low | review | 2026-07-29 |
| dfb__${98991*97996}__::.x | 3.02 | Low | review | 2026-07-29 |
| <%={{={@{#{${dfb}}%> | 3.17 | Low | review | 2026-07-29 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 3.13 | Low | review | 2026-07-29 |
| v3.69304079< | 3.14 | Low | review | 2026-07-29 |
| v3.6'"()&%<zzz><ScRiPt >7AjZ(9220)</ScRiPt> | 3.07 | Low | review | 2026-07-29 |
| v3.6&n919386=v984373 | 2.92 | Low | review | 2026-07-29 |
| v3.6 | 3.68 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA
14a4ff5b4e55…
Force block
— not fired
Score recovered
no
Elapsed
22.0s