Perplexity Chat Exporter - Export Perplexity to PDF, Markdown, JSON
imicnaojoabefckkfhailgkllodbnjjf
Risk Score
4.51
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but does not scope to this extension and admits no data collection — 481-char stub, third-party silence; +9.0 privacy.
- Brand impersonation: 'perplexity' in name, developer is unaffiliated gmail user with no developer name — +2.0 reputation.
- CSP connect-src is '*' (wildcard) allowing exfil to any host; 8 innerHTML DOM-XSS sinks across content scripts.
- JS external hosts include buy.stripe.com, assets.grok.com, chat.deepseek.com, x.com — 12 distinct hosts far beyond stated function.
- Yandex cloud/OAuth endpoints (Russian jurisdiction) included as integration targets; free-webmail dev with no verified identity.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'perplexity'; developer_domain is gmail.com, confirmed_owner=false.
- csp_connect_wildcard manifest connect-src * data: blob: filesystem: — wildcard allows outbound connections to any host, enabling data exfil.
- dom_xss_sinks crx 8 innerHTML assignments from variables across options.js, popup.js, cocounsel.js, claude.js, renderer.js, shared.js, helpers.js, pdfobject.
- privacy_policy_stub api Policy fetched (481 chars), scope_extension=false, data_collection=false — not scoped to this extension.
- free_webmail_no_dev_name store developer_email=neocrtxai@gmail.com, developer_name empty, not verified publisher.
- yandex_endpoints manifest host_permissions include oauth.yandex.com, oauth.yandex.ru, cloud-api.yandex.net — Russian-jurisdiction data storage.
- install_url_hijack crx install_url_hijack=true; extension opens a URL on install (target null — not resolved).
- search_engine_count_3 api threat_intel.search_engine_count=3 (google.com, yandex.com, yandex.ru) — anomalous for a chat exporter.
Permissions Breakdown
- downloads medium Enables file download to user filesystem; matches stated export function.
- downloads.open medium Can open downloaded files; extends downloads surface slightly.
- storage low Local preference storage; low risk.
- identity medium OAuth token access; used for Dropbox/Notion/Google integrations.
- activeTab low Scoped to active tab only; limited reach.
- https://*.amazonaws.com/* medium Broad AWS host access; could reach many services beyond stated use.
- https://*.googleusercontent.com/* medium Access to Google user content; used for image export.
- https://*.perplexity.ai/* medium Core function host; reads chat content for export.
- https://ai-chat-exporter-api-perplexity-*.run.app/* medium Developer-controlled backend API; data transits third-party server.
- https://api.dropboxapi.com/* medium Dropbox integration; can upload exported files.
- https://api.notion.com/* medium Notion integration; can write exported data.
- https://cloud-api.yandex.net/* medium Yandex cloud storage; Russian-jurisdiction endpoint adds geo-risk.
- https://content.dropboxapi.com/* medium Dropbox content upload endpoint.
- https://oauth.yandex.com/* medium Yandex OAuth; Russian-jurisdiction auth flow.
- https://oauth.yandex.ru/* medium Yandex OAuth (.ru TLD); Russian-jurisdiction auth flow.
- https://www.googleapis.com/* medium Google APIs; used for Drive/Sheets export integrations.
Pillar Scores
Permissions3.50
Reputation6.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 13:29
Listing SHA
6f54d6db84c7…
Force block
— not fired
Score recovered
no
Elapsed
—