Manuals Viewer
ieihbaicbgpebhkfebnfkdhkpdemljfb
Risk Score
7.24
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Free-webmail dev (gmail) with no verified identity, broad all-URLs scripting capability — high option value for malicious pivot.
- Uninstall URL hijack flag set — extension registers a 3rd-party URL on uninstall, a monetization/tracking pattern.
- Privacy policy admits data collection AND third-party sharing but is NOT scoped to this extension — worst-case disclosure.
- Extension stale 25 months with no rating data and only 138 installs — tail-attack-surface with high permissions.
- No CSP combined with broad scripting + tabs + declarativeNetRequest enables full man-in-the-middle of every page.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() call detected — routes users to 3rd-party on uninstall; monetization/tracking signal.
- broad_host_permissions manifest host_permissions and content_scripts_matches both set to http://* + https://* giving full page access.
- free_webmail_developer store Developer email wilkinsonvalentine272@gmail.com; no verified publisher badge; numbered-alias pattern.
- privacy_policy_generic_admits_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy.
- maintenance_stale store Last updated June 2024, 25 months ago — 24-36mo band triggers +8.5 maintenance score.
- install_perm_anomaly api 138 installs with HIGH-tier permissions: small_install_high_perm=true, tail_attack_surface=true.
- no_csp manifest content_security_policy is null (MV3 strict default applies, no extra network penalty, but amplifies other risks).
- numbered_alias_email store Developer email matches numbered-alias pattern (wilkinsonvalentine272) — webstore +3.0 signal.
Permissions Breakdown
- storage low Stores local extension data; low standalone risk.
- tabs medium Can read tab URLs and metadata across all open tabs.
- scripting high Allows JS injection into any page via broad host_permissions; high capability.
- declarativeNetRequest medium Can intercept and redirect network requests declaratively.
- http://*/* high Broad host access: content scripts run on every HTTP page.
- https://*/* high Broad host access: content scripts run on every HTTPS page.
Pillar Scores
Permissions8.00
Reputation8.50
Network4.00
Webstore7.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-29 13:19
Listing SHA
a299796f567c…
Force block
— not fired
Score recovered
no
Elapsed
—