NFT to silly jpeg
hcajgiblhhpbgbmlgioljefhmoolebjn
Risk Score
6.04
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope to this extension; classified as collecting and sharing data with third parties.
- Extension last updated January 2022 (53 months); abandoned with broad host access is a supply-chain acquisition risk.
- Broad host_permissions *://*/* + content_scripts on all URLs gives full DOM access to every page.
- No CSP declared; MV3 provides some default protections but no explicit policy increases attack surface.
- Small install count (121) with HIGH-tier permissions flagged as tail-attack-surface anomaly.
Evidence
- broad_host_permissions manifest host_permissions and content_scripts_matches both set to *://*/* — runs on every site.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store Last updated January 2022, 53 months ago. No updates since release.
- no_csp manifest content_security_policy is null; no explicit CSP declared.
- install_perm_anomaly api 121 installs with high-tier host permission; tail_attack_surface=true, small_install_high_perm=true.
- external_host_is_gd crx js_external_hosts contains is.gd (URL shortener) — unclear why a text-replacement extension contacts this.
- featured_by_google store is_featured_by_google=true; provides mild reputation credit but does not override stale/policy concerns.
- no_bad_hosts_no_cves crx cve_findings_raw and bad_host_hits both empty; code_findings_raw empty; obfuscation_score=0.
Permissions Breakdown
- host_permissions: *://*/* high Broad host access allows content script injection on every site the user visits.
- content_scripts_matches: *://*/* high Content script runs on all URLs; combined with broad host perms, full DOM read/write everywhere.
Pillar Scores
Permissions5.50
Reputation4.50
Network2.00
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA
0650e90ce92e…
Force block
— not fired
Score recovered
no
Elapsed
19.0s