J2TEAM Security
hmlcjjclebjnfohgmgikjfnbmfkigocc
Risk Score
3.76
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Free-webmail dev (gmail) with no listed developer name; accountability gap for 300K-install security tool.
- cookies + broad host permissions (<all_urls>): can read session cookies from any site visited.
- webRequest + scripting + broad hosts: full traffic intercept and script injection capability across all sites.
- install_url_hijack and uninstall_url_hijack flags detected; potential for redirect abuse on install/remove.
- 12 external JS hosts including ad/social domains (facebook, adsmanager.facebook.com); geo diversity spans 4 countries.
Evidence
- free_webmail_dev store developer_email=junookyo@gmail.com; no developer_name; gmail raises accountability concern for 300K users.
- verified_publisher+featured store verified_publisher=true and is_featured_by_google=true; discounts reputation risk partially.
- install_url_hijack+uninstall_url_hijack crx install_url_hijack=true, uninstall_url_hijack=true (targets null); pattern warrants review.
- broad_host_plus_cookies manifest cookies + http://*/* + https://*/* + webRequest: can read/write cookies and intercept requests site-wide.
- external_hosts_social_ad crx js_external_hosts includes adsmanager.facebook.com, connect.facebook.net, www.facebook.com among 12 hosts.
- geo_diversity_4_countries api JS hosts span CA, IN, SG, US — 4 countries; +1.5 network penalty applies.
- privacy_policy_adequate api Policy fetched, scoped, data_collection+retention+third_party_sharing all disclosed; third_party_silence=false.
- dom_xss_sinks crx 2 innerHTML-from-variable findings in bundled chunks; CSP present (script-src self) limits exploitation.
Permissions Breakdown
- tabs medium Access to tab URLs/titles; moderate sensitivity for a security tool.
- notifications low Display alerts; low abuse potential.
- contextMenus low Adds right-click menu items; low risk.
- cookies high Read/write cookies across all origins; combined with broad host access = high risk.
- storage low Local extension data only.
- unlimitedStorage low Extended local quota; low risk alone.
- webRequest high Observe/intercept all HTTP requests; core to security tools but high capability.
- alarms low Scheduled tasks; low risk.
- scripting high Programmatic script injection into pages; combined with broad hosts = high risk.
- declarativeNetRequest medium Declarative request blocking; less powerful than webRequestBlocking.
- sidePanel low UI panel only; low risk.
- http://*/* high Broad host access to all HTTP sites.
- https://*/* high Broad host access to all HTTPS sites.
Pillar Scores
Permissions6.50
Reputation3.50
Network3.50
Webstore4.00
Maintenance0.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| v3.6 | 3.76 | Low | allow | 2026-06-16 |
| v3.4-rev | 3.05 | Low | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
e165dad35f60…
Force block
— not fired
Score recovered
no
Elapsed
31.4s