Decodo(Smartproxy) Extension
hdemabfejemmmicoabglpocdmmkjphpo
Risk Score
4.00
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Proxy+cookies+browsingData+<all_urls> combo gives full traffic interception and session-hijack capability.
- Privacy policy (smartproxy.com) is not scoped to this extension and admits third-party data sharing.
- No CSP on MV3 extension with 10 external JS hosts including bit.ly (affiliate/cloaking link).
- Developer name field empty; policy domain (smartproxy.com) differs from extension branding (decodo.com).
- Geo-diverse JS hosts (4 countries: CA, DE, IN, US) increases supply-chain attack surface.
Evidence
- HIGH permission cluster manifest proxy+webRequest+webRequestAuthProvider+browsingData+cookies+privacy+<all_urls> — maximum traffic and session access.
- No CSP declared crx content_security_policy is null on MV3; +2.0 network penalty applied per v2 calibration.
- affiliate_hits: bit.ly api bit.ly listed as generic short-link redirector / affiliate cloaking in threat_intel.
- Privacy policy not extension-scoped store policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
- Verified publisher + featured by Google store Both signals present; caps reputation floor at 2.0 after discounts.
- Geo-diversity: 4 countries api JS hosts span CA, DE, IN, US; +1.5 network per rule (14), category VPN exempt — not applied.
- No code findings / obfuscation crx obfuscation_score=0.0, code_findings_raw=[], code quality pillar = 0.00.
- 10 external JS hosts including developer docs crx addons.mozilla.org, github.com, reactjs.org, redux.js.org etc — >3 distinct domains, +1.5 network.
Permissions Breakdown
- proxy high Routes all browser traffic through attacker-controlled endpoint if compromised.
- webRequest high Can observe all HTTP/S requests across every site.
- webRequestAuthProvider high Intercepts and supplies proxy authentication credentials.
- browsingData high Can delete cookies, cache, history — broad destructive capability.
- cookies high Read/write cookies for all sites; combined with <all_urls> is critical.
- privacy high Can alter browser privacy settings (WebRTC, referrers, etc.).
- tabs medium Reads tab URLs and metadata across all open tabs.
- storage low Local extension data storage; low standalone risk.
- <all_urls> high Host permission covering every URL; amplifies all other high permissions.
Pillar Scores
Permissions6.50
Reputation2.00
Network3.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA
e423b0055ef6…
Force block
— not fired
Score recovered
no
Elapsed
26.0s