Spotify artist's all songs
jdicfniianljldbajoghhnilmnghgmno
Risk Score
4.82
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Spotify brand impersonation by gmail developer with no verified identity or business domain.
- Privacy policy is generic Google account policy — does not scope to this extension; admits data collection and 3rd-party sharing.
- Three host permissions on unverified dev-controlled *.spotify-artists-all-songs.xyz subdomain cluster enable data exfiltration.
- Free-webmail developer (gmail) with no business website or verified publisher badge raises accountability gap.
- Sentry + PostHog telemetry bundled via sourcemaps; usage policy opaque given inadequate privacy policy.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands=['spotify'], confirmed_owner=false, dev domain=gmail.com
- generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true
- unverified_dev_domain_host_perms manifest 3 host_permissions on *.spotify-artists-all-songs.xyz under gmail dev control
- free_webmail_developer store developer_email=xdpugachevx@gmail.com; no business website; not verified publisher
- telemetry_libraries crx Sentry and PostHog detected via sourcemaps in service-worker.js; versions unknown
- featured_by_google store is_featured_by_google=true; partial trust signal but doesn't override brand impersonation or privacy gap
- no_bad_hosts_or_affiliates api threat_intel bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no active malicious infra detected
- cve_none crx cve_findings_raw empty; no CVE exposure from bundled libraries
Permissions Breakdown
- storage low Persists extension state locally; minimal risk alone.
- identity medium Can obtain OAuth tokens; used for Spotify auth but grants access to user identity.
- tabs medium Can read tab URLs/titles; moderate reach over browsing context.
- host: *://api.spotify-artists-all-songs.xyz/ high Third-party domain controlled by individual gmail dev; not Spotify official. Data exfil risk.
- host: *://s.spotify-artists-all-songs.xyz/ high Same throwaway-domain pattern; additional endpoint under unverified dev control.
- host: *://p.spotify-artists-all-songs.xyz/ high Third sub-domain on same unverified domain; expands attack surface.
- host: *://api.spotify.com/ medium Official Spotify API; expected for stated function.
- host: https://accounts.spotify.com/authorize low OAuth authorization endpoint; expected for login flow.
Pillar Scores
Permissions2.90
Reputation8.00
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA
d965ad731eaa…
Force block
— not fired
Score recovered
no
Elapsed
23.2s