YouTube Shopping
ighjodkhjaliganonnlmdedfgnomaebi
Risk Score
2.82
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic policy (policies.google.com) — not scoped to this extension; scope_extension==false with data_collection+third_party_sharing==true triggers +10.0 privacy.
- brand_mention flags 'youtube' as impersonation (confirmed_owner==false); developer email is @google.com but verified_publisher==false, creating unresolved ownership ambiguity.
- No CSP present (MV3 default mitigates somewhat, but no explicit policy declared).
- Install count 50K provides moderate blast radius if extension is ever compromised or transferred.
- Generic Google privacy policy admits data collection and third-party sharing without extension-specific scope.
Evidence
- brand_impersonation_flag store brand_mention.is_impersonation=true for 'youtube'; confirmed_owner=false despite @google.com email and non-verified publisher status.
- generic_privacy_policy store policies.google.com/privacy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
- no_csp manifest content_security_policy is null; MV3 provides strict default but no explicit CSP declared. Network +2.0 (MV2+no-CSP rule does NOT apply to MV3).
- minimal_permissions manifest Only 'activeTab' declared; no host_permissions, no content_scripts. Very low capability surface.
- clean_code_scan crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[]. No malicious indicators detected.
- no_cve_findings crx cve_findings_raw=[]; no vulnerable libraries bundled.
- recently_updated store months_since_update=2; maintenance pillar score=0.0.
- unverified_publisher store verified_publisher=false, is_featured_by_google=false; no reputation discounts applicable.
Permissions Breakdown
- activeTab low Only accesses the current tab on explicit user action; minimal persistent access.
Pillar Scores
Permissions0.30
Reputation5.00
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| v3.6 | 2.82 | Low | review | 2026-06-16 |
| v3.4-rev | 2.76 | Low | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA
aa584a1c76b9…
Force block
— not fired
Score recovered
no
Elapsed
19.2s