Pay with BitPay
jkjgekcefbkpogohigkgooodolhdgcda
Risk Score
4.61
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Broad content_scripts on http://*/*+https://*/*oliciting all pages; scripting permission amplifies reach.
- Privacy policy fetched but does NOT scope to this extension; admits data collection and third-party sharing (D rule → +10.0).
- Uninstall URL hijack flag set (uninstall_url_hijack=true) — could route users to third-party post-removal.
- dom_sink_innerhtml_userctrl in bundled React bundle — DOM-XSS sink executed across all sites.
- developer_name empty; no verified publisher badge; no brand confirmation despite bitpay.com domain.
Evidence
- broad_host_permissions manifest host_permissions and content_scripts_matches both cover http://* and https://* — runs on every site.
- uninstall_url_hijack crx uninstall_url_hijack=true; target unknown — potential post-uninstall redirect to third party.
- privacy_policy_generic store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 D rule +10.0.
- dom_xss_sink crx innerHTML assigned from variable in js/options.bundle.js — DOM-XSS risk on options page.
- google_analytics_telemetry crx connect-src includes google-analytics.com; monetization_hits lists it as telemetry tier only.
- no_developer_name store developer_name field empty; email integrations@bitpay.com suggests legitimate org but unverified.
- js_external_hosts crx 8 external hosts in CSP/JS: bitpay.com, fonts.googleapis.com, gravatar.com, github.com, reactjs.org, etc.
- cve_findings_empty crx No CVEs detected in bundled libraries; cve_findings_raw is empty.
Permissions Breakdown
- activeTab low Scoped to current tab on user action only.
- storage low Local preference/settings storage, low impact.
- scripting high Can inject JS into pages; combined with broad host_permissions this is high risk.
- http://*/* high Broad host access across all HTTP sites for content script injection.
- https://*/* high Broad host access across all HTTPS sites for content script injection.
Pillar Scores
Permissions5.00
Reputation5.00
Network2.50
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA
c4e4ccfa187f…
Force block
— not fired
Score recovered
no
Elapsed
23.3s