Money Blocker
ilpgbnfccheldpfalcgljiomfeelppma
Risk Score
6.41
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- 41 months without update — zombie extension with broad host access on all URLs.
- Privacy policy is Google's own policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail developer (gmail), no developer name or business website — unverifiable identity.
- Content scripts injected on <all_urls> with innerHTML sink present — DOM-XSS risk on every page.
- External JS hosts include S3 bucket (sleep-giants.s3.us-east-1.amazonaws.com) and reactjs.org — remote resource references.
Evidence
- months_since_update=41 store Last updated April 2023; >36 months stale — maintenance pillar max 10.0.
- privacy_policy_generic api Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- developer_identity store Developer name empty, email is free Gmail (moneyblocker.org@gmail.com), no business domain — Reputation floor 7.5.
- dom_sink_innerhtml_userctrl crx innerHTML sink in chunk-4d7ba024.js; csp_present=false amplifies DOM-XSS risk.
- broad_host_access manifest host_permissions *://*/* plus content_scripts <all_urls> — full read/write on every page.
- js_external_hosts crx References reactjs.org, sleep-giants.s3.us-east-1.amazonaws.com, npmjs.com — 3 external domains, 2 countries.
- install_perm_anomaly api Only 246 installs but has HIGH-tier host permissions — small_install_high_perm and tail_attack_surface true.
- csp_absent_mv3 manifest csp_present=false on MV3; no explicit CSP declared, amplifying innerHTML sink risk.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata across all browsing.
- declarativeNetRequest medium Allows blocking/redirecting network requests; appropriate for adblock but powerful.
- *://*/* high Broad host access to all URLs; combined with content_scripts gives full page read/write.
- content_scripts <all_urls> high Script injected into every page; reads DOM across all sites the user visits.
Pillar Scores
Permissions4.50
Reputation7.50
Network3.00
Webstore4.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 05:31
Listing SHA
357f9ce9b623…
Force block
— not fired
Score recovered
no
Elapsed
—