Inbox Firewall
iomcnbgephfbopcnhgiophdaobmikfep
Risk Score
3.29
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's own policy (not scoped to this extension); admits data collection and 3rd-party sharing without extension-specific disclosure.
- Content script on Gmail means extension can read sensitive email content; API endpoint api.inboxfirewall.com may receive email data.
- No CSP present (MV3 default is stricter but csp_present=false) combined with innerHTML DOM-XSS sink in content/ui.js.
- New/low-profile developer (Neurear IT); no ratings, no install count, unverified publisher.
- Generic Google privacy policy URL used — does not describe what this extension collects, retains, or shares.
Evidence
- privacy_policy_generic store Privacy URL points to Google's own policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores +10.0 per v3.5 rule D.
- dom_xss_sink crx content/ui.js: tt.innerHTML = content — DOM-XSS sink with no CSP; scored +2.0 under FIX B.
- gmail_host_permission manifest Content script on https://mail.google.com/* allows reading email body; API endpoint may exfiltrate it.
- no_installs_no_ratings store Install count empty, rating=0 — no social proof; unverified publisher.
- no_cve_findings crx cve_findings_raw is empty; no known-vulnerable libraries detected.
- recently_updated store Last updated April 28 2026, months_since_update=2; maintenance risk = 0.
- no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty; developer domain resolves and not throwaway.
- mv3_no_csp_declared manifest MV3 with csp_present=false; no explicit CSP amplifies DOM-XSS risk in content script.
Permissions Breakdown
- storage low Stores extension state locally; low direct harm.
- activeTab low Scoped to user-initiated interaction only.
- host:https://mail.google.com/* medium Content script on Gmail; reads email content for phishing detection.
- host:https://api.inboxfirewall.com/* medium Extension backend API; email data may be sent here for analysis.
- host:https://www.inboxfirewall.com/* low Marketing/info site; low risk on its own.
Pillar Scores
Permissions2.50
Reputation5.00
Network2.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA
d60c36dc8b09…
Force block
— not fired
Score recovered
no
Elapsed
23.3s