Anti phising safer browsing for chrome
jkokgpghakemlglpcdajghjjgliaamgc
Risk Score
4.34
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but admits data collection + third-party sharing without extension-specific scope — rated maximum privacy risk.
- Uninstall URL hijack to browserguard.net; install redirect also active — behavioural monetization signals.
- Content scripts injected on <all_urls> with innerHTML DOM-XSS sinks and no CSP — elevated code-quality risk.
- No developer display name despite verified-publisher badge; 18-month stale cap limits verified-publisher discount.
- Privacy policy scope_extension=false with data_collection+third_party_sharing=true triggers D-clause max privacy penalty.
Evidence
- privacy_policy_D_clause api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D-clause).
- uninstall_url_hijack crx chrome.runtime.setUninstallURL to https://browserguard.net/uninstall → +3.0 webstore.
- install_url_hijack crx onInstalled opens https://browserguard.net/install → +2.0 webstore.
- dom_sink_innerhtml_no_csp crx Two innerHTML sinks found, csp_present=false → dom_sink score elevated to +2.0 per FIX B.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true, has_high_tier_permission with 7k installs → +1.0 webstore.
- no_developer_name store developer_name is empty string; verified_publisher=true caps reputation discount per 0c (months_since_update=18).
- maintenance_stale store months_since_update=18 → 12-24mo band → +6.0 maintenance.
- host_permissions_all_urls manifest <all_urls> host + content_scripts on all URLs; category=Security gives justified-broad discount applied.
Permissions Breakdown
- declarativeNetRequest medium Allows blocking/redirecting network requests; core to stated security function.
- storage low Local key-value storage only; minimal risk.
- <all_urls> (host_permission) high Full access to every site the user visits; content scripts injected on all URLs.
- content_scripts <all_urls> high Scripts run on every page; DOM manipulation possible site-wide.
Pillar Scores
Permissions4.50
Reputation4.50
Network3.50
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:53
Listing SHA
43343de206e7…
Force block
— not fired
Score recovered
no
Elapsed
—