Search Everywhere with Google Bard/Gemini
hnadleianomnjcoeplifgbkiejchjmah
Risk Score
4.52
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Brand impersonation: extension name/title falsely implies Google/Gemini/Bard ownership with no verified publisher status.
- Google's generic privacy policy linked — does not scope data collection to this extension; admits data collection and third-party sharing.
- <all_urls> host permission with content_scripts on every page — broad read/write capability for a gmail-developer extension.
- Developer uses free webmail (bardplugin@gmail.com) with no verified business identity; no domain age signal available.
- Install URL hijack redirects to gemini.google.com/app on install, reinforcing false brand association.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[google,gemini,bard]; confirmed_owner=false; developer_domain=gmail.com.
- privacy_policy_generic store Policy is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case privacy tier.
- host_permissions_all_urls manifest host_permissions=[<all_urls>] + content_scripts_matches=[<all_urls>]; full cross-site content access.
- free_webmail_developer store developer_email=bardplugin@gmail.com; no business website; domain_age_ct.queried=false (free webmail).
- install_url_hijack crx install_url_hijack=true; target=https://gemini.google.com/app — redirects user to Google brand page on install.
- js_external_hosts crx 8 external hosts: api.openai.com, be.chatgptbygoogle.com, chat.openai.com, chatgpt.com, chrome.google.com, gemini.google.com, github.com, www.google.com.
- no_csp manifest content_security_policy=null; MV3 default CSP applies but no explicit restriction on connect-src.
- ai_extension_page_content store AI category extension with <all_urls> content scripts — high risk of page-content exfiltration to AI endpoints.
Permissions Breakdown
- notifications medium Can push unsolicited notifications to user; medium nuisance/phishing vector.
- storage low Stores local data; low standalone risk.
- sidePanel low Opens side panel UI; low risk in isolation.
- <all_urls> (host_permission) high Content scripts injected on every site; full page read/write capability.
Pillar Scores
Permissions6.50
Reputation8.50
Network5.50
Webstore6.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| fsssiedxn77eea3e2zafdsaxax><!--></ScRiPt>asddn77eea3e2zsssiedx | 4.59 | Medium | block | 2026-08-25 |
| sssiedn384b4dd0dp727562726963xsx | 4.43 | Medium | block | 2026-08-25 |
| v3.6 | 4.52 | Medium | block | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
9991e5e3eadf…
Force block
— not fired
Score recovered
no
Elapsed
22.2s