Allow CSP: Content-Security-Policy
hnojoemndpdjofcdaonbefcfecpjfflh
Risk Score
5.33
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is generic Google account policy (scope_extension==false, data_collection==true, third_party_sharing==true) — worst-case Privacy score.
- Install and uninstall URL hijack flags set — extension opens/redirects on install/uninstall events.
- Developer uses free Gmail account with no verifiable business identity; featured badge partially mitigates.
- <all_urls> host permission paired with declarativeNetRequest allows CSP stripping on every site, significant attack surface.
- External JS host webbrowsertools.com detected; unknown third-party domain increases supply-chain risk.
Evidence
- install_url_hijack crx install_url_hijack=true; extension opens a URL on install — target unresolved.
- uninstall_url_hijack crx uninstall_url_hijack=true; extension sets uninstall redirect URL — target unresolved.
- privacy_policy_generic store Policy is Google account policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email mujo.hydrov@gmail.com; no verified business domain; domain_age_ct not queried.
- external_js_host crx js_external_hosts=[webbrowsertools.com]; unknown third-party domain in extension code.
- broad_host_permission manifest host_permissions=[<all_urls>] combined with declarativeNetRequest; can strip CSP headers on all sites.
- is_featured_by_google store Extension carries Google Featured badge, providing partial legitimacy signal.
- operator_cluster_email_siblings api sibling_counts_by_dim.dev_email=2; same Gmail account linked to 2 extensions; compound sibling_count=0.
Permissions Breakdown
- storage low Stores extension settings locally; minimal risk.
- declarativeNetRequest medium Can modify/block network requests including CSP headers; significant capability.
- <all_urls> (host_permission) high Broad host access enabling declarativeNetRequest rules to apply on every site visited.
Pillar Scores
Permissions6.50
Reputation6.50
Network2.00
Webstore8.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| v3.6 | 5.33 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.73 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
bdcc57a4225e…
Force block
— not fired
Score recovered
no
Elapsed
20.6s