LastPass: Free Password Manager
hdokiejnpimakedhajhdlcegeplioahd
Risk Score
3.68
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true: Privacy pillar scores 10.0.
- Broad host access (http://*/* + https://*/*) combined with cookies and webRequest enables full page and credential interception.
- Dynamic script injection (script_src_dynamic) and innerHTML sinks in React bundle introduce DOM-XSS surface across all visited pages.
- CSP connect-src is very broad, covering multiple IdP/SSO domains, DataDog telemetry, and pwnedpasswords.com.
- LastPass has a significant public breach history (2022); high-value credential-manager target warrants elevated scrutiny.
Evidence
- privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic policy admits sharing without extension scope.
- broad_host_access manifest host_permissions http://*/* + https://*/* with content_scripts on same; justified for password manager autofill.
- featured_by_google store is_featured_by_google=true; applies -1.5 reputation discount (featured badge).
- no_verified_publisher store verified_publisher=false; no -3.0 reputation discount applied.
- script_src_dynamic crx Webpack runtime creates dynamic <script> elements; common in SPA bundles but raises code-quality score.
- dom_sink_innerhtml crx Two innerHTML sinks in React and federated-login bundles; CSP present limits exploitation but not eliminated.
- cve_findings_empty crx No CVEs found in bundled libraries despite jquery 3.6.0 and react 16.13.1 being present.
- threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain lastpass.com resolves and not throwaway.
Permissions Breakdown
- scripting high Can inject JS into any page; core to password manager but high capability.
- tabs medium Access to tab URLs and metadata across all tabs.
- notifications low Can display system notifications; low direct data risk.
- contextMenus low Adds right-click menu items; minimal risk.
- storage low Local extension storage; expected for password manager.
- unlimitedStorage low Removes storage quota; expected for vault data.
- webNavigation medium Observes navigation events across all pages; needed for autofill triggers.
- webRequest high Can observe all HTTP requests; broad surveillance capability.
- webRequestAuthProvider high Can intercept HTTP auth challenges; elevated credential-handling risk.
- offscreen low Background document for audio/DOM tasks; low risk in context.
- alarms low Scheduled background tasks; minimal risk.
- cookies high Read/write cookies across all origins; high risk paired with broad host access.
- http://*/* high Content script on all HTTP pages; necessary for autofill but very broad.
- https://*/* high Content script on all HTTPS pages; necessary for autofill but very broad.
Pillar Scores
Permissions5.50
Reputation2.50
Network2.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure0.00
Scoring History
| sssiedn5393d766dp727562726963xsx | 3.66 | Low | review | 2026-08-30 |
| 'fsssiedxa sssiedx | 4.17 | Medium | review | 2026-08-20 |
| fsssiedxa$"sssiedx | 3.87 | Low | review | 2026-08-20 |
| v3.6"onmouseover=XJX5(97492)" | 4.29 | Medium | review | 2026-08-05 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 4.39 | Medium | review | 2026-08-05 |
| v3.6&n979076=v974800 | 4.14 | Medium | review | 2026-08-05 |
| %76%33%2E%36%39%32%37%33%22%28%29%3B%7D%5D%39%32%34%33 | 2.81 | Low | review | 2026-08-04 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 4.07 | Medium | review | 2026-08-04 |
| v3.6&n940129=v912328 | 4.10 | Medium | review | 2026-08-04 |
| %F6"onmouseover=5qLv(95245)// | 4.54 | Medium | review | 2026-07-29 |
| dfb{{98991*97996}}xca | 5.01 | Medium | review | 2026-07-29 |
| <th:t="${dfb}#foreach | 4.41 | Medium | review | 2026-07-29 |
| v3.6&n945879=v954514 | 4.55 | Medium | review | 2026-07-29 |
| %27fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.08 | Medium | review | 2026-07-28 |
| fsssiedxa<sssiedx | 4.17 | Medium | review | 2026-07-28 |
| fsssiedxa'sssiedx | 3.86 | Low | review | 2026-07-28 |
| sssieddrubricxsx | 2.86 | Low | review | 2026-07-28 |
| v3.6 | 3.68 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA
03a9250501a9…
Force block
— not fired
Score recovered
no
Elapsed
33.4s