Save to Google Drive
gmbmikajjgmnabiglmofipeabaddhgne
Risk Score
4.17
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Generic Google privacy policy does not scope data collection to this extension — admits collection and 3rd-party sharing.
- <all_urls> + webRequest + scripting + pageCapture combination gives broad capability over every site visited.
- developer_name field is empty in listing metadata; no verified publisher badge.
- privacy_policy_classification: scope_extension=false, data_collection=true, third_party_sharing=true → triggers +10 privacy pillar.
- Rating 3.9 at 5M installs indicates some user dissatisfaction; no red-flag reviews detected but warrants monitoring.
Evidence
- host_permissions_all_urls manifest <all_urls> host permission granted; amplifies webRequest, scripting, pageCapture by ×1.2.
- privacy_policy_generic_google store Policy at policies.google.com: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
- developer_identity store developer_email=drive-extension-support@google.com; developer_name empty; brand_mention confirmed_owner=true, not impersonation.
- recognized_org_discount store google.com domain, confirmed_owner; -2.0 reputation discount applied (capability gate: HIGH perms present, caps to -1.0 per 0b).
- csp_absent_mv3 manifest content_security_policy=null; MV3 has strict default so +2.0 MV2 network penalty does NOT apply.
- code_findings_empty crx code_findings_raw=[]; obfuscation_score=0.0; no malicious signals detected.
- cve_findings_empty crx cve_findings_raw=[]; no known vulnerable libraries detected.
- maintenance_3_6mo store months_since_update=11; falls in 6-12mo band → +3.5.
Permissions Breakdown
- contextMenus low Adds right-click menu items; low data risk.
- identity medium Can obtain OAuth tokens for signed-in Google account.
- printerProvider low Enables print-to-Drive; narrow scope.
- notifications low Shows desktop notifications; no data exfil risk alone.
- pageCapture high Can capture full page content as MHTML — high data access.
- storage low Local extension storage; low risk.
- tabs medium Access to tab URLs and titles across all open tabs.
- webRequest high Observe all network requests; paired with <all_urls> elevates risk.
- scripting high Can inject scripts into any page when combined with <all_urls>.
- <all_urls> high Broad host access amplifies webRequest, scripting, pageCapture risk.
Pillar Scores
Permissions5.80
Reputation2.00
Network2.00
Webstore2.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiedn892cfe36dp727562726963xsx | 4.73 | Medium | review | 2026-09-04 |
| xx pfsssiedxa$'sssiedx | 4.51 | Medium | review | 2026-08-15 |
| %27fsssiedxa$'sssiedx | 4.51 | Medium | review | 2026-08-15 |
| "fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.87 | Medium | review | 2026-08-15 |
| fsssiedxa$"sssiedx | 4.66 | Medium | review | 2026-08-15 |
| <fsssiedxa"sssiedx | 4.33 | Medium | review | 2026-08-14 |
| <fsssiedxi"sssiedx | 4.55 | Medium | review | 2026-08-14 |
| <fsssiedxi$"sssiedx | 4.78 | Medium | review | 2026-08-14 |
| <fsssiedxh xx psssiedx | 4.73 | Medium | review | 2026-08-13 |
| <fsssiedxh'sssiedx | 4.58 | Medium | review | 2026-08-13 |
| <fsssiedxh$"sssiedx | 4.83 | Medium | review | 2026-08-13 |
| 'fsssiedxg xx psssiedx | 4.70 | Medium | review | 2026-08-13 |
| 'fsssiedxgfdsaxax><!--></ScRiPt>asddsssiedx | 4.64 | Medium | review | 2026-08-13 |
| 'fsssiedxg$"sssiedx | 4.73 | Medium | review | 2026-08-13 |
| 4.54 | Medium | review | 2026-08-13 | |
| $"fsssiedxg | 4.72 | Medium | review | 2026-08-13 |
| $"fsssiedxg sssiedx | 4.53 | Medium | review | 2026-08-13 |
| fsssiedxg$"sssiedx | 4.49 | Medium | review | 2026-08-13 |
| <fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx | 4.77 | Medium | review | 2026-08-13 |
| <fsssiedx{'sssiedx | 4.67 | Medium | review | 2026-08-13 |
| fsssiedx<sssiedx | 5.14 | Medium | review | 2026-08-13 |
| v3.6"sTYLe='zzz:Expre/**/SSion(BE5t(9092))'bad=" | 4.55 | Medium | review | 2026-08-05 |
| dfb{{98991*97996}}xca | 4.86 | Medium | review | 2026-08-05 |
| <th:t="${dfb}#foreach | 4.49 | Medium | review | 2026-08-05 |
| v3.6&n997672=v948774 | 4.72 | Medium | review | 2026-08-05 |
| fsssiedxa xx psssiedx | 4.58 | Medium | review | 2026-07-30 |
| fsssiedxa | 4.28 | Medium | review | 2026-07-30 |
| sssieddrubricxsx | 4.50 | Medium | review | 2026-07-30 |
| v3.6</script><script>GF2r(9124)</script> | 4.39 | Medium | review | 2026-07-29 |
| v3.6"sTYLe='zzz:Expre/**/SSion(GF2r(9593))'bad=" | 4.47 | Medium | review | 2026-07-29 |
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%47%46%32%72%28%39%34%31%37%34%29%22 | 4.18 | Medium | review | 2026-07-29 |
| dfb[[${98991*97996}]]xca | 4.50 | Medium | review | 2026-07-29 |
| bfg5924<s1﹥s2ʺs3ʹhjl5924 | 4.44 | Medium | review | 2026-07-29 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 4.49 | Medium | review | 2026-07-29 |
| <%={{={@{#{${dfb}}%> | 4.34 | Medium | review | 2026-07-29 |
| v3.6 | 4.17 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA
57f4a6c40259…
Force block
— not fired
Score recovered
no
Elapsed
22.6s