Spotify Player+
haibeacocpobdaiimnfhjbkiggfacehc
Risk Score
5.42
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Impersonates Spotify brand without confirmed ownership — is_impersonation=true.
- Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — wholly inadequate for this extension.
- Extension is abandoned: 53 months since last update (>36mo), zombie risk for any future compromise or sale.
- Triple-stale fingerprint: >24mo stale + MV2-adjacent maintenance concern + Google generic policy.
- No rating count available; rating 3.9 provides limited trust signal for 6K installs.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'spotify'; developer not confirmed_owner.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- abandoned_extension store Last updated January 2022; months_since_update=53 (>36mo maintenance floor).
- developer_domain api framecore.se resolves, looks_throwaway=false; no verified publisher badge.
- no_bad_hosts crx threat_intel bad_host_hits, affiliate_hits, monetization_hits all empty.
- clean_code crx code_findings_raw empty, obfuscation_score=0.0, cve_findings_raw empty.
- csp_present manifest CSP: script-src 'self'; object-src 'self' — strict, no remote script sources.
- low_permissions manifest Only identity + storage declared; no host_permissions, no content_scripts.
Permissions Breakdown
- identity low OAuth token access; scoped to Spotify auth flow, low standalone risk.
- storage low Local extension storage only, no cross-origin data exposure.
Pillar Scores
Permissions0.60
Reputation7.00
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA
091fbd5d4e6e…
Force block
— not fired
Score recovered
no
Elapsed
19.4s