PopUpOFF - Popup and overlay blocker
ifnkdbpmgkdbfklnbfidaackdenlmhgh
Risk Score
5.27
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy (scope_extension=false, admits data collection & 3rd-party sharing) — +10.0 privacy pillar.
- Extension last updated 34 months ago — high staleness risk, no recent security patches.
- Broad content_scripts on <all_urls> with no CSP; no MV2 penalty (MV3) but surface is wide.
- Developer email is free webmail (gmail.com) with empty developer_name; limited accountability.
- Description promises ad/popup blocking but lacks declarativeNetRequest/webRequest — description mismatch flagged.
Evidence
- privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — not scoped to this extension.
- staleness store Last updated August 2023; 34 months since update triggers +8.5 maintenance score.
- broad_host_permissions manifest host_permissions include http://*/ and https://*/ with content_scripts on <all_urls>.
- no_csp manifest content_security_policy is null; MV3 so no +2.0 network penalty, but no inline-script protection.
- developer_identity store developer_name is empty; email is RomanistHere@gmail.com (free webmail). Verified publisher badge present.
- description_mismatch store description_promise reports mismatch: promises ad-blocking but lacks declarativeNetRequest/webRequest.
- install_url_hijack crx onInstalled opens https://popupoff.org/tutorial?source=chrome — own domain, low severity but flagged.
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, no CVEs, no bad/affiliate/monetization hosts.
Permissions Breakdown
- activeTab low Scoped to user-invoked tab; low blast radius.
- storage low Local settings persistence only.
- tabs medium Can read tab URLs/titles across all open tabs.
- contextMenus low UI-only menu injection, no data access.
- http://*/ high Broad host access to all HTTP sites via content scripts.
- https://*/ high Broad host access to all HTTPS sites via content scripts.
Pillar Scores
Permissions4.00
Reputation3.50
Network2.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA
d9e05cb3fbb7…
Force block
— not fired
Score recovered
no
Elapsed
22.6s