Better Color Picker - pick any color in Chrome
gpibachbddnihfkbjcfggbejjgjdijeb
Risk Score
4.42
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy hosted on freeprivacypolicy.com: not scoped to this extension, admits data collection and third-party sharing — worst-case generic policy.
- Uninstall URL hijack detected (target null but flag set); classic monetization/tracking signal.
- Broad host permissions (http://*/*, https://*/*) with content scripts on all sites; colour picker function doesn't require this reach.
- Free-webmail developer (gmail.com) with no verified publisher badge; no business website or domain identity.
- External JS host 'better-color-picker.guru' contacted; unverified domain could be a future supply-chain vector.
Evidence
- uninstall_url_hijack crx uninstall_url_hijack=true; +3.0 Webstore per rubric for 3rd-party uninstall URL.
- privacy_policy_generic_with_collection_and_sharing api freeprivacypolicy.com policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5-D).
- broad_host_permissions manifest host_permissions=[http://*/*, https://*/*] + content_scripts on all URLs; colour picker does not justify this.
- free_webmail_developer store Developer email kauffman.be72@gmail.com; numbered alias pattern (be72); no verified publisher.
- external_js_host crx js_external_hosts=[better-color-picker.guru]; single external domain, no bad-host hit but unverified.
- no_csp manifest csp_present=false on MV3; no additional MV2 penalty but CSP absent increases injection surface.
- operator_cluster_singleton api sibling_count=0; no cluster amplifier applied.
- cve_findings_empty crx No CVEs detected; cve_pillar_score=0.0.
Permissions Breakdown
- storage low Stores user preferences locally; low impact.
- declarativeNetRequest medium Can block/modify network requests; medium risk without webRequestBlocking.
- http://*/* high Broad host access across all HTTP sites; content scripts run everywhere.
- https://*/* high Broad host access across all HTTPS sites; content scripts run everywhere.
Pillar Scores
Permissions5.00
Reputation6.50
Network3.00
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:09
Listing SHA
f88e0120b622…
Force block
— not fired
Score recovered
no
Elapsed
—