Proton Pass: Free Password Manager
ghmbeldphafepmbegfdlkpapadhbakde
Risk Score
3.32
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy hosted on proton.me does not scope data handling to this extension specifically (scope_extension=false), triggering max privacy score.
- webRequest + scripting + broad host_permissions (<all_urls>) allows interception and injection across every site visited.
- innerHTML DOM-XSS sinks present in 6 JS files (notification, settings, dropdown, onboarding, internal, popup); CSP is present but does not fully mitigate.
- developer_name is empty; protonmail.zendesk.com is a support subdomain, not a first-party publisher domain — reduces accountability.
- Uninstall URL hijack flag is set; target URL is null so risk is limited, but the mechanism is present.
Evidence
- broad_host_permissions manifest host_permissions include http://*/* and https://*/* paired with scripting and webRequest.
- privacy_policy_scope_missing api privacy_policy_classification: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- dom_xss_sinks crx 6 files contain dom_sink_innerhtml_userctrl; CSP is present so FIX B base +0.5 applies per occurrence, capped.
- uninstall_url_hijack store uninstall_url_hijack=true but target=null; mechanism present, destination unknown.
- developer_identity store developer_name empty; email is support@protonmail.zendesk.com (Zendesk subdomain, not proton.me).
- featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied.
- cve_findings crx cve_findings_raw=[]; CVE pillar = 0.0.
- no_obfuscation_no_bad_hosts crx obfuscation_score=0.0; bad_host_hits=[], affiliate_hits=[], monetization_hits=[].
Permissions Breakdown
- activeTab low Scoped to user-initiated interaction; minimal risk.
- alarms low Schedules background tasks; low standalone risk.
- offscreen low Creates offscreen documents; limited scope.
- scripting medium Can inject scripts into pages; paired with broad host_permissions elevates risk.
- storage low Local extension storage; expected for a password manager.
- unlimitedStorage low Extended storage quota; expected for credential vault.
- webNavigation medium Monitors page navigation; expected for autofill triggers.
- webRequest high Observes all network requests across all URLs; powerful interception capability.
- https://*/* high Broad host access to all HTTPS sites; paired with scripting/webRequest.
- http://*/* high Broad host access to all HTTP sites; combined with scripting/webRequest.
Pillar Scores
Permissions3.50
Reputation3.00
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA
bd5aea75658c…
Force block
— not fired
Score recovered
no
Elapsed
29.6s