Eye Dropper
hmdcmlfkchdmnmnmheododdhjedfccka
Risk Score
3.58
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false and third_party_sharing=true with no retention disclosure — scores maximum privacy risk.
- Uninstall URL hijack redirects to extensions-hub.com monetization partner page.
- Developer uses free Gmail address with no 'Offered by' name despite 1M installs and verified publisher badge.
- 8 external JS hosts referenced including www.extensions-hub.com; no CSP on MV3.
- Policy admits third-party sharing without scoping to this extension — data handling opaque.
Evidence
- uninstall_url_hijack crx setUninstallURL points to https://www.extensions-hub.com/partners/uninstalled/ — monetization/tracking redirect.
- privacy_policy_third_party_sharing_no_scope api Policy fetched; scope_extension=false, data_collection=false, third_party_sharing=true, retention=false → +10.0 privacy.
- free_webmail_developer store Developer email hello.extensionshub@gmail.com; developer_name empty; 1M installs but no verified org identity.
- verified_publisher store is_featured_by_google=true and verified_publisher=true; applies reputation discount but capped due to monetization hits via uninstall URL.
- js_external_hosts crx 8 external hosts in JS including www.extensions-hub.com, svelte.dev, gomakethings.com; country_count=2.
- install_reach store 1,000,000 installs; +1.0+1.0 webstore reach. Featured by Google.
- no_cve_no_bad_hosts api cve_findings_raw empty, bad_host_hits empty, affiliate_hits empty, code_findings_raw empty.
- wayback_error api Wayback ownership check returned fetch_error:ConnectionError; ownership_changed=false by default.
Permissions Breakdown
- activeTab low Grants access only to current tab on user action; limited scope.
- storage low Local data persistence for settings; low risk.
- scripting medium Can inject scripts into pages; combined with activeTab limits scope but still capable.
Pillar Scores
Permissions1.30
Reputation5.50
Network2.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| fsssiedx<sssiedx | 3.25 | Low | review | 2026-08-20 |
| sssieddrubricxsx | 2.72 | Low | review | 2026-08-20 |
| v3.6"><script>qIeY(9263)</script> | 3.27 | Low | review | 2026-08-05 |
| dfb__${98991*97996}__::.x | 3.26 | Low | review | 2026-08-05 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 3.55 | Low | review | 2026-08-05 |
| v3.69317178< | 3.07 | Low | review | 2026-08-05 |
| v3.6&n981497=v921526 | 3.83 | Low | review | 2026-08-05 |
| v3.6'"()&%<zzz><ScRiPt >ypf5(9300)</ScRiPt> | 3.42 | Low | review | 2026-07-29 |
| v3.6&n900678=v925967 | 3.57 | Low | review | 2026-07-29 |
| v3.6 | 3.58 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
924c0376d91e…
Force block
— not fired
Score recovered
no
Elapsed
20.9s