The Education District
jghlbgpehejkbenneehiialadabidfpb
Risk Score
6.07
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- nativeMessaging with unrecognized publisher gives OS-level code execution surface on every user machine.
- Extension last updated 39 months ago — zombie risk, no security patches since April 2023.
- file:///* host permission exposes all local files to extension content scripts.
- Privacy policy is a generic iubenda template: scope_extension==false, no collection or retention disclosure.
- Small install base (988) with HIGH-tier permissions (install_perm_anomaly) raises tail-attack-surface concern.
Evidence
- nativeMessaging + publisher_recognized==false manifest nativeMessaging declared; native_messaging_check.publisher_recognized=false → +3.0 permissions.
- file:///* host permission manifest Broad local filesystem access granted via host_permissions and content_scripts_matches.
- months_since_update=39 (>36mo) store Last updated April 2023; maintenance pillar = 10.0 (zombie). No changelog visible.
- install_url_hijack=true crx onInstalled opens third-party URL; +2.0 webstore per install-URL-hijack rule.
- no CSP (csp_present=false, MV3) manifest MV3 has strict default; no additional network penalty but inline execution unguarded.
- privacy policy generic iubenda api scope_extension=false, data_collection=false, third_party_silence=true → privacy pillar 9.0.
- install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; 988 installs with nativeMessaging.
- verified_publisher=true, developer domain resolves store virtway.com resolves, verified publisher; reputation discount applied but capped due to staleness >18mo.
Permissions Breakdown
- nativeMessaging high Allows arbitrary communication with host OS apps; publisher_recognized==false adds +3.0 native-messaging penalty.
- tabs medium Exposes tab URLs and metadata across browsing session.
- https://*.public.theeducationdistrict.com/* low Scoped to own service domain; limited blast radius.
- https://*.cms.theeducationdistrict.com/* low Scoped to own CMS domain; limited blast radius.
- file://*/* high Access to all local files on the filesystem is a high-impact capability.
Pillar Scores
Permissions6.50
Reputation3.50
Network2.00
Webstore4.50
Maintenance10.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-15 14:17
Listing SHA
406648d57c3f…
Force block
— not fired
Score recovered
no
Elapsed
—