Extension Manager
gjldcdngmdknpinoemndlidpcabkggco
Risk Score
7.71
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- management permission allows silently disabling/removing all other installed extensions — critical control plane.
- Uninstall and install URL hijacks redirect to extensions-manager.com; gmail dev email is unverifiable.
- Privacy policy is a generic freeprivacypolicy.com template: not scoped to this extension, admits data collection and 3rd-party sharing.
- 26 months since last update; stale MV3 extension with 100K users is acquisition/compromise target.
Evidence
- management_permission manifest management perm grants full control over all installed extensions — highest-impact single permission.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL → https://extensions-manager.com/feedback.html (3rd-party redirect on uninstall).
- install_url_hijack crx onInstalled opens https://extensions-manager.com (3rd-party redirect on install).
- gmail_dev_no_verified_publisher store Developer email q2268444203@gmail.com with numbered alias; not a verified publisher.
- generic_privacy_policy api freeprivacypolicy.com template: scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store 26 months since last update with 100K installs — zombie fingerprint, high acquisition risk.
- google_analytics_telemetry crx www.google-analytics.com in js_external_hosts; telemetry-tier monetization hit.
- function_constructor crx new Function() call in vendor bundle; low-severity but noteworthy given no CSP.
Permissions Breakdown
- management high Can enable/disable/uninstall all other extensions — extremely powerful control surface.
- tabs medium Access to tab URLs and navigation; moderate risk for an extension manager.
- storage low Local data persistence; low risk on its own.
- unlimitedStorage low Removes storage quota cap; minor escalation of storage risk.
Pillar Scores
Permissions7.50
Reputation7.50
Network3.50
Webstore8.00
Maintenance8.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| fsssiedxn0046680cza"n0046680czsssiedx | 4.73 | Medium | review | 2026-09-08 |
| sssiedn1616b78edp727562726963xsx | 4.58 | Medium | review | 2026-09-08 |
| fsssiedxna59a9ed7zafdsaxax><!--></ScRiPt>asddna59a9ed7zsssiedx | 4.80 | Medium | review | 2026-09-06 |
| fsssiedxn32b68265za'n32b68265zsssiedx | 4.58 | Medium | review | 2026-09-06 |
| fsssiedxn327e91e6za | 4.54 | Medium | review | 2026-09-06 |
| sssiednf47e9f3cdp727562726963xsx | 4.27 | Medium | review | 2026-09-06 |
| v3.6'"()&%<zzz><ScRiPt >1Bkt(9711)</ScRiPt> | 7.80 | High | block | 2026-07-29 |
| v3.6 | 7.71 | High | review | 2026-07-03 |
Bookkeeping
Rubric v3.6
Scored at 2026-07-03 04:42
Listing SHA
0764f6488f16…
Force block
— not fired
Score recovered
no
Elapsed
—