SplitPay – Payment Plan Builder
gmpbnbaadoblnejmacmdifimonhfahpo
Risk Score
4.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- Developer uses free Gmail with no name or verified identity; no business accountability.
- Backend is a developer-controlled Cloudflare Worker (splitpay-pro.saydiburkhon4.workers.dev) — opaque data sink.
- No CSP on MV3 extension contacting external hosts; no code-level controls visible.
- Extremely low install count (13) with no verifiable identity raises tail-attack-surface concern.
Evidence
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- free_webmail_no_dev_name store developer_email=saydiburkhon4@gmail.com, developer_name empty; free-webmail + no identity → reputation floor 7.5.
- developer_controlled_worker manifest host_permissions include splitpay-pro.saydiburkhon4.workers.dev — opaque Cloudflare Worker backend controlled by anonymous dev.
- no_csp crx content_security_policy is null; MV3 has strict default but no explicit CSP declared.
- network_external_hosts crx js_external_hosts: script.google.com, splitpay-pro.saydiburkhon4.workers.dev, splitpay-share.saydiburkhon4.workers.dev — 3 distinct domains.
- no_bad_hosts_no_cves api bad_host_hits=[], cve_findings_raw=[], affiliate_hits=[], monetization_hits=[] — no active threat signals detected.
- very_low_installs store Only 13 installs; rating=5 with no rating_count — insufficient signal for trust.
- recently_updated store months_since_update=2; maintenance score 0.0.
Permissions Breakdown
- storage low Local key-value store; no cross-origin read capability.
- host: https://script.google.com/* medium Allows fetch to Google Apps Script; could exfil data via developer-controlled script.
- host: https://splitpay-pro.saydiburkhon4.workers.dev/* medium Developer-controlled Cloudflare Worker; opaque backend with no accountability.
Pillar Scores
Permissions2.00
Reputation7.50
Network4.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA
c7d23b75b05d…
Force block
— not fired
Score recovered
no
Elapsed
20.5s