DirectStayz: Book hotels directly, save money and unlock benefits
imbiddkienbjbdoaclimfhdhbpbhnabf
Risk Score
5.01
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, yet admits data collection and third-party sharing (+10.0 privacy).
- Uninstall and install URL hijack flags set, indicating extension opens/redirects to 3rd-party URLs on install/uninstall events.
- Affiliate network host (www.awin1.com) in js_external_hosts signals monetization via affiliate-link injection on booking.com.
- Free-webmail developer (gmail) with no verified business; developer domain is gmail.com, no independent business presence.
- Stale update (14 months) combined with MV3 and no CSP raises residual governance risk.
Evidence
- install/uninstall URL hijack crx uninstall_url_hijack=true and install_url_hijack=true; targets not resolved but pattern is monetization/tracking.
- affiliate host detected crx www.awin1.com present in js_external_hosts — affiliate network indicating commission-based link injection.
- generic Google privacy policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free-webmail developer, no verified publisher store Developer email matcha.squad1@gmail.com; verified_publisher=false; is_featured_by_google=false.
- multiple external JS hosts beyond stated function crx 10 external hosts including plausible-1.matcha-squad.xyz, pocketbase-1.matcha-squad.xyz, edge.truesign.ai, awin1.com.
- stale extension store Last updated May 2025; months_since_update=14, in the 12-24mo maintenance band (+6.0).
- no content_security_policy manifest csp_present=false on MV3 extension; no CSP declared.
- obfuscation and code findings clean crx obfuscation_score=0.0; code_findings_raw empty; 12 JS files scanned with no AST findings.
Permissions Breakdown
- storage low Stores local state; no user-data exfil risk on its own.
- host: https://api.getdirecto.com/* low Narrow host permission to single API domain matching stated function.
- content_scripts: booking.com medium Runs JS on booking.com pages; can read page content including search/hotel data.
Pillar Scores
Permissions1.30
Reputation6.50
Network3.50
Webstore7.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-08 14:39
Listing SHA
eb0e5865d597…
Force block
— not fired
Score recovered
no
Elapsed
—