GIF Maker
jdhodfggggnlbjhgdjggokbhbecefadl
Risk Score
3.52
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Free-webmail developer (gmail) with no verified business identity raises accountability concerns.
- install_url_hijack and uninstall_url_hijack flags set — onInstalled/onUninstalled redirect behaviour present.
- No CSP on MV3 extension; DOM-XSS sink (innerHTML) in bundled gifshot.js vendor lib.
- Privacy policy scoped to extension but no data retention disclosed; third-party sharing not addressed.
- Low rating (3.2) may reflect functional or trust issues; small user base limits crowdsourced signal.
Evidence
- free_webmail_developer store Developer email hovie.keller@gmail.com — free webmail, no verified business domain.
- install_url_hijack crx install_url_hijack=true; target null — onInstalled redirect behaviour flagged.
- uninstall_url_hijack crx uninstall_url_hijack=true; target null — onUninstalled redirect behaviour flagged.
- dom_sink_innerhtml_userctrl crx gifshot.js: span.innerHTML=text — DOM-XSS sink; no CSP present to mitigate.
- no_csp crx content_security_policy is null; MV3 default CSP applies but no explicit hardening.
- privacy_policy_retention_missing store Policy fetched, extension-scoped, no data collection claimed, but retention not disclosed.
- is_featured_by_google store Extension carries Google Featured badge — partial trust signal.
- low_rating store Rating 3.2; review red-flag check found 0 explicit malware mentions.
Permissions Breakdown
- storage low Stores user preferences/GIF data locally; low intrinsic risk.
- contextMenus low Adds right-click menu entry; no data access implied.
Pillar Scores
Permissions0.60
Reputation6.50
Network2.00
Webstore3.50
Maintenance3.50
Privacy6.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA
907c7033876a…
Force block
— not fired
Score recovered
no
Elapsed
19.2s