daily.dev | Where developers discover what's next
jlmpjdjjbgclbocgajdjefcidcncaied
Risk Score
4.17
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true: policy admits broad collection without scoping to this extension.
- Dynamic script injection (script_src_dynamic) in 3 bundle files — remote code loading risk even with strict CSP.
- NewTab override with 400K installs gives high reach; every user's new tab is controlled by this extension.
- No developer name listed; developer_email domain (daily.dev) resolves but no verified-publisher badge.
- Uninstall URL hijack flag set (uninstall_url_target null but signal is true); potential post-removal tracking.
Evidence
- privacy_policy_admits_3p_sharing_no_scope api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
- script_src_dynamic_x3 crx 3 bundle files create dynamic <script> elements; counts as script_src_dynamic → +3.0 code quality.
- dom_sink_innerhtml_x2 crx 2 files with innerHTML from variable; CSP present so +0.5 each, but csp_present mitigates FIX B escalation.
- newtab_override manifest chrome_url_overrides.newtab=index.html; +2.0 webstore (NewTab override). Category-matched discount applied.
- uninstall_url_hijack store uninstall_url_hijack=true (target null); +3.0 webstore per rubric, but target unknown — applied conservatively.
- featured_by_google store is_featured_by_google=true → -2.0 reputation (Featured badge).
- no_developer_name store developer_name is empty string → +1.0 reputation.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
Permissions Breakdown
- scripting medium Allows dynamic script injection into pages; medium risk when scoped to host_permissions only.
- host_permissions: https://daily.dev/, https://*.daily.dev/, https://dailynow.co/, https://*.dailynow.co/ low Scoped to developer-owned domains only; narrow blast radius.
- chrome_url_overrides: newtab medium Replaces every new tab; high reach but category-matched (NewTab news reader).
- content_scripts: https://*.daily.dev/*, https://daily.dev/* low Content scripts scoped to developer-owned domain only.
Pillar Scores
Permissions2.50
Reputation3.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Scoring History
| "fsssiedxa sssiedx | 2.86 | Low | review | 2026-08-20 |
| fsssiedxa$"sssiedx | 2.63 | Low | review | 2026-08-20 |
| <fsssiedxa xx psssiedx | 4.26 | Medium | block | 2026-08-01 |
| <fsssiedxa | 4.22 | Medium | review | 2026-08-01 |
| <fsssiedxa$'sssiedx | 4.43 | Medium | review | 2026-08-01 |
| <fsssiedxa'sssiedx | 4.49 | Medium | review | 2026-08-01 |
| <fsssiedxa$"sssiedx | 4.36 | Medium | review | 2026-08-01 |
| xx pfsssiedxa sssiedx | 4.23 | Medium | review | 2026-08-01 |
| "fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.47 | Medium | review | 2026-08-01 |
| "fsssiedxa$"sssiedx | 4.44 | Medium | review | 2026-08-01 |
| %27fsssiedxa sssiedx | 4.73 | Medium | review | 2026-08-01 |
| "fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.25 | Medium | review | 2026-08-01 |
| 4.45 | Medium | review | 2026-08-01 | |
| fsssiedxa<sssiedx | 4.47 | Medium | review | 2026-08-01 |
| fsssiedxa'sssiedx | 4.55 | Medium | review | 2026-07-30 |
| sssieddrubricxsx | 4.65 | Medium | review | 2026-07-30 |
| v3.6 | 4.17 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA
e6310466e2ab…
Force block
— not fired
Score recovered
no
Elapsed
31.9s