Send to Telegram
jejaagembgeeipilhpjpndednmcphenh
Risk Score
5.00
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Telegram brand impersonation: developer is unaffiliated gmail user, not Telegram owner.
- Privacy policy is Google's generic policy — does not scope to this extension at all (fetched+collects+shares, not scoped).
- Install URL hijack: onInstalled opens /pages/embed.html (3rd-party redirect pattern).
- Free-webmail developer with no verified business identity; high Reputation floor.
- Stale extension (21 months since update) with no CSP declared (MV3 mitigates partially).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=[telegram], confirmed_owner=false, dev domain=gmail.com.
- privacy_policy_generic store Policy URL is Google myaccount generic page; scope_extension=false, data_collection=true, third_party_sharing=true.
- install_url_hijack crx install_url_hijack=true, target=/pages/embed.html; onInstalled opens redirect page.
- free_webmail_developer store developer_email=rustyredvalve@gmail.com; no verified publisher, no business domain.
- maintenance_stale store months_since_update=21; falls in 12-24mo band (+6.0 maintenance).
- no_csp crx content_security_policy=null; MV3 applies strict default but no explicit CSP declared.
- external_hosts crx js_external_hosts=[api.telegram.org, stackoverflow.com]; 2 distinct registrable domains contacted.
- featured_by_google store is_featured_by_google=true; partial reputation mitigation but does not override impersonation.
Permissions Breakdown
- contextMenus low Adds right-click menu items; low standalone risk, consistent with stated function.
- storage low Local key-value storage only; no cross-origin data exposure.
Pillar Scores
Permissions0.60
Reputation7.50
Network2.00
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA
9c75d6154b28…
Force block
— not fired
Score recovered
no
Elapsed
18.9s