Auto Resolution Quality for YouTube™
hdangknebhddccoocjodjkbgbbedeaam
Risk Score
7.09
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall URL hijack and install URL hijack both flagged — classic monetization/tracking shell behavior.
- Privacy policy admits data collection and third-party sharing without scoping to this extension (D rule → +10.0 privacy).
- Developer domain eokoko.com does not resolve — accountability gap undermines verified-publisher trust (0c cap applies).
- YouTube brand impersonation confirmed by brand_mention; developer not a confirmed YouTube/Google owner.
- Extension is 25 months stale with small install base but high-tier permissions — tail attack surface risk.
Evidence
- uninstall_url_hijack + install_url_hijack crx Both install and uninstall URL hijacks flagged; targets null but pattern matches monetization shell behavior.
- developer_domain_not_resolving api eokoko.com does not resolve; verified-publisher discount capped at -1.0 per invariant 0c (v3.5).
- privacy_policy_admits_3rd_party_sharing_no_scope store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule +10.0 privacy.
- brand_impersonation_youtube store brand_mention.is_impersonation=true; developer not confirmed YouTube owner → +2.0 reputation.
- stale_extension store 25 months since update → maintenance +8.5; also triggers triple-stale fingerprint check.
- install_perm_anomaly api 994 installs, high-tier permissions: small_install_high_perm=true, tail_attack_surface=true.
- webRequest_plus_all_urls manifest webRequest + <all_urls> + scripting + content_scripts on <all_urls> = full page interception capability.
- no_developer_name store developer_name is empty string; reduces accountability despite verified_publisher=true.
Permissions Breakdown
- webRequest high Can observe all HTTP traffic; paired with <all_urls> significantly expands attack surface.
- tabs medium Access to tab URLs and metadata across all open tabs.
- activeTab medium Temporary access to active tab content; lower risk but stacks with scripting.
- scripting high Programmatic script injection into pages; combined with <all_urls> = broad code execution.
- declarativeNetRequest medium Can modify/block network requests declaratively.
- storage low Local data persistence; low risk in isolation.
- alarms low Scheduling; enables periodic background tasks.
- <all_urls> (host_permission) high Broad host access enables content scripts and webRequest on every site the user visits.
Pillar Scores
Permissions7.50
Reputation7.00
Network2.00
Webstore8.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:08
Listing SHA
dfb8af88e4e1…
Force block
— not fired
Score recovered
no
Elapsed
—