Okta Browser Plugin
glnpjglilkicbckjpbgcfkogebgllemb
Risk Score
4.41
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetch failed (SSLError): policy adequacy unverifiable; scored as missing — highest privacy risk.
- Broad host access (https://*/, http://*/) combined with cookies+scripting+webRequest enables full session/credential access on any site.
- 5 new Function() constructor calls across background, shared, settings, newtab, and popover scripts — dynamic code execution surface.
- No developer name listed and unverified publisher for a high-privilege SSO extension with 5M installs.
- Uninstall and install URL hijack flags set; even with null targets this is an anomalous signal for an enterprise auth plugin.
Evidence
- privacy_policy_fetch_failed api Privacy policy URL returned SSLError on fetch; classified as fetched=false → pillar scored at 10.0 (no policy).
- broad_host_permissions manifest https://*/ and http://*/ grant access to every site; paired with cookies, scripting, webRequest.
- multiple_function_constructor crx 5 distinct new Function() calls in background.js, shared.js, newtab, settings-page, popover — dynamic eval surface.
- dom_xss_sink crx innerHTML assigned from variable in shared.js without apparent sanitization — DOM-XSS risk.
- no_developer_name store developer_name is empty string; verified_publisher=false for 5M-install enterprise SSO extension.
- install_uninstall_url_hijack manifest uninstall_url_hijack=true and install_url_hijack=true; targets null but flags are set.
- pendo_analytics_host crx app.pendo.io and data.pendo.io in js_external_hosts — third-party analytics touching enterprise SSO flows.
- no_cve_findings crx cve_findings_raw empty; no vulnerable bundled libraries detected.
Permissions Breakdown
- tabs medium Allows reading tab URLs/titles across all sites — necessary for SSO redirect detection.
- cookies high Can read/write cookies on all HTTPS/HTTP origins; paired with broad host access — critical surface.
- storage low Local extension storage; low risk on its own.
- unlimitedStorage low Allows larger storage quota; low additional risk.
- webRequest high Intercepts all HTTP/HTTPS requests across all sites; core SSO intercept capability.
- webNavigation medium Tracks navigation events across all tabs; needed for SSO flow detection.
- scripting high Can inject scripts into any page; broad host access makes this very high capability.
- declarativeNetRequestWithHostAccess high Can block/modify network requests on all hosts; powerful request manipulation.
- webRequestAuthProvider high Can handle HTTP auth challenges; allows credential interception surface.
- https://*/ high Broad host access over all HTTPS origins; combined with cookies/scripting is critical reach.
- http://*/ high Broad host access over all HTTP origins; extends capability to non-TLS sites.
Pillar Scores
Permissions5.50
Reputation4.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Scoring History
| sssiedn0351b020dp727562726963xsx | 4.74 | Medium | review | 2026-09-09 |
| v3.6 | 4.41 | Medium | review | 2026-08-27 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 09:34
Listing SHA
583014f9ab6c…
Force block
— not fired
Score recovered
no
Elapsed
—