PDF Reader and Editor
ieepebpjnkhaiioojkepfniodjmjjihl
Risk Score
4.87
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Gmail developer with no business identity — free-webmail email raises accountability concerns.
- Privacy policy is Google's generic account policy: fetched, not scoped to this extension, admits data collection and 3rd-party sharing → +10.0.
- Content scripts injected on <all_urls> combined with install-URL hijack opens broad page-data exposure.
- 12 distinct external JS hosts (including obscure domains) loaded by extension, far beyond stated PDF function.
- install_url_hijack detected — onInstalled opens third-party URL.
Evidence
- free_webmail_developer store Developer email emano.waldeck@gmail.com; no verified business domain; triggers free-webmail reputation penalty.
- privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — not scoped to extension; data_collection+third_party_sharing true; scope_extension false.
- broad_host_access_with_content_scripts manifest host_permissions and content_scripts_matches both list <all_urls>; scripts run on every page visited.
- install_url_hijack crx install_url_hijack=true; onInstalled opens /data/pdf.js/web/viewer.html — third-party page opened on install.
- many_external_js_hosts crx 12 external JS hosts including campustecnologicoalgeciras.es, foersom.com, www.africau.edu, www.tecxoft.com — broad for a PDF reader.
- no_bad_hosts_no_cve api threat_intel bad_host_hits empty; cve_findings_raw empty; obfuscation_score 0.0; code_findings_raw empty — no malicious signals detected.
- featured_by_google store is_featured_by_google=true provides partial trust signal; offsets some reputation risk.
- geo_diversity_low api Only 2 countries (CA, IN) for JS hosts; geo_diversity rule not triggered (<4 countries).
Permissions Breakdown
- storage low Standard local data persistence; minimal risk.
- contextMenus low Adds right-click menu items; low capability.
- favicon low Reads favicon URLs; low risk.
- <all_urls> (host_permissions) high Broad host access enabling content scripts on every site.
- content_scripts <all_urls> high Script injection into every page visited; high capability surface.
Pillar Scores
Permissions5.50
Reputation6.50
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssieddrubricxsx | 4.41 | Medium | review | 2026-07-31 |
| v3.6 | 4.87 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA
8a4f4a0db216…
Force block
— not fired
Score recovered
no
Elapsed
26.9s