Spotify player
gokeibibpoonnkpojbkknfnjgojdjlhm
Risk Score
5.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Spotify brand impersonation by unverified gmail developer — high risk of credential harvesting or account abuse.
- Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — +10.0 privacy pillar.
- Low rating (1.7) on a Spotify-named extension with gmail dev email signals potential abuse.
- Unknown host superwhomp.com in js_external_hosts — unrecognized third-party endpoint with no explanation.
- Stale extension (21 months since update) with brand impersonation and no verified publisher accountability.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'spotify'; developer is unverified gmail account, not Spotify AB.
- free_webmail_developer store Developer email help.nextgensoultions@gmail.com — gmail with no verified business domain.
- generic_privacy_policy store Privacy policy is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- unknown_external_host crx js_external_hosts includes superwhomp.com — unrecognized domain, no threat_intel hit but unexplained.
- low_rating store Rating 1.7 — very low; insufficient rating_count data but signal is negative.
- stale_extension store Last updated September 2024; months_since_update=21, in 6-12mo maintenance band.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false — no accountability signals.
- cve_findings crx cve_findings_raw empty; no CVE exposure detected.
Permissions Breakdown
- storage low Stores local extension state; minimal risk.
- identity low Used for OAuth token acquisition; scoped to Spotify auth flow.
- https://api.spotify.com/* medium Host permission to Spotify API; enables reading/controlling user Spotify account.
- https://accounts.spotify.com/* medium Host permission for Spotify auth; required for OAuth but grants auth-page access.
Pillar Scores
Permissions1.30
Reputation8.50
Network2.00
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA
4efef9904a11…
Force block
— not fired
Score recovered
no
Elapsed
19.7s