simple-modify-headers
gjgiipmpldkpbdfjkgofildhapegmmic
Risk Score
5.67
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- declarativeNetRequestWithHostAccess + *://*/* allows modification/blocking of all HTTP requests across every site.
- 26 months since last update — zombie extension with broad host access is high-risk acquisition target.
- Privacy policy is Google's generic account policy (scope_extension=false, admits data collection and 3rd-party sharing): scores 10.
- No CSP declared (MV3 default only) combined with innerHTML DOM-XSS sink in popup/config.js.
- Free-webmail developer (gmail) with no verified publisher badge and generic non-scoped privacy policy.
Evidence
- broad_host_access manifest host_permissions=[*://*/*] paired with declarativeNetRequestWithHostAccess — can intercept all requests.
- stale_extension store Last updated June 2024; months_since_update=26. Abandoned/zombie risk.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- dom_xss_sink crx popup/config.js: innerHTML assigned from variable without sanitization; no CSP to mitigate.
- no_csp manifest csp_present=false on MV3; default MV3 CSP applies but no explicit extension-level CSP hardening.
- free_webmail_developer store Developer email didierfred@gmail.com; no verified publisher badge; no business domain.
- featured_badge store is_featured_by_google=true; partial reputation credit applied.
- no_cve_findings crx cve_findings_raw=[]; no known vulnerable bundled libraries detected.
Permissions Breakdown
- activeTab low Grants access to active tab only on user gesture; limited scope.
- tabs medium Can read tab URLs and metadata across all tabs.
- storage low Local config storage; low standalone risk.
- declarativeNetRequest medium Can modify/block network requests declaratively.
- declarativeNetRequestWithHostAccess high HIGH: modifies requests on all hosts combined with *://*/* host permission.
- *://*/* high Broad host access across all URLs; enables request interception on any site.
Pillar Scores
Permissions6.00
Reputation5.50
Network2.50
Webstore1.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-03 07:16
Listing SHA
6bbe46f22525…
Force block
— not fired
Score recovered
no
Elapsed
—