WPS PDF - Read, Edit, Fill, Convert, and AI Chat PDF with Ease
kdpelmjpfafjppnhbloffcjpeomlnpah
Risk Score
4.45
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- nativeMessaging with unrecognized publisher: extension can bridge to OS-level native app with no publisher sanity check.
- cookies + scripting + <all_urls> + webRequest: full read/write/intercept of all sites and sessions.
- Privacy policy not scoped to extension; fetched policy admits data collection and third-party sharing (+10 privacy).
- No CSP (MV3 strict default applies but csp_present=false noted); new Function() in background.js raises code-quality concern.
- AI category processing page content at scale; 7M installs amplifies blast radius of any compromise or policy change.
Evidence
- nativeMessaging + publisher_recognized=false crx Extension uses nativeMessaging but native_messaging_check.publisher_recognized is false; adds +3.0 permissions.
- cookies + <all_urls> manifest HIGH permission cookies paired with broad host access triggers x1.2 amplifier on permissions pillar.
- privacy_policy scope_extension=false, data_collection=true, third_party_sharing=true api Policy fetched but not scoped to this extension, admits data collection and third-party sharing → Privacy pillar +10.0.
- uninstall_url_hijack=true crx chrome.runtime.setUninstallURL() redirects user on uninstall; adds +3.0 webstore signal.
- function_constructor in background.js crx new Function() in background script is a code-quality risk signal (+2.5 code quality).
- is_featured_by_google=true, rating=4.5 store Google Featured badge and high rating provide partial trust signal; reputation floor applied.
- looks_throwaway=true on wps.com api developer_domain_info.looks_throwaway=true despite wps.com resolving; adds +1.5 webstore.
- AI extension processing page content at 7M installs store +2.5 webstore for AI/Gen-AI category processing page content; +1.0 installs>1M; -0.5 popularity-trust.
Permissions Breakdown
- webRequest high Intercept/observe all network requests; paired with <all_urls> is maximum-reach.
- webNavigation medium Observe all page navigations across every site visited.
- storage low Local extension data storage; standard low-risk capability.
- tabs medium Read URL, title, and status of all open tabs.
- nativeMessaging high Communicate with host-OS native app; publisher_recognized==false amplifies risk.
- declarativeNetRequest medium Modify/block network requests; lower risk than webRequestBlocking alone.
- gcm medium Receive push messages from developer servers silently.
- cookies high Read/write cookies on all URLs; combined with <all_urls> = critical surface.
- notifications low Display desktop notifications; limited direct data-access risk.
- scripting high Inject arbitrary JS into any page; paired with <all_urls> is very high risk.
- <all_urls> (host_permissions) high Broad host access amplifies every HIGH permission by x1.2 multiplier.
Pillar Scores
Permissions9.00
Reputation4.50
Network6.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| %27fsssiedxa sssiedx | 6.11 | High | review | 2026-08-13 |
| fsssiedxa<sssiedx | 6.22 | High | block | 2026-08-13 |
| %76%33%2E%36%39%36%32%39%22%28%29%3B%7D%5D%39%35%39%32 | 6.44 | High | block | 2026-08-05 |
| dfb__${98991*97996}__::.x | 6.09 | High | review | 2026-08-05 |
| v3.6&n926860=v956300 | 6.24 | High | review | 2026-08-05 |
| <fsssiedxf"sssiedx | 4.59 | Medium | block | 2026-08-04 |
| <fsssiedxf$"sssiedx | 5.95 | Medium | review | 2026-08-04 |
| <fsssiedx{$'sssiedx | 6.17 | High | block | 2026-08-04 |
| xx pfsssiedxisssiedx | 4.43 | Medium | block | 2026-08-04 |
| "fsssiedxifdsaxax><!--></ScRiPt>asddsssiedx | 6.06 | High | block | 2026-08-04 |
| 'fsssiedxi$'sssiedx | 4.41 | Medium | review | 2026-08-04 |
| 'fsssiedxi$'sssiedx | 4.64 | Medium | review | 2026-08-04 |
| "fsssiedxi$'sssiedx | 4.54 | Medium | review | 2026-08-04 |
| fsssiedxi<sssiedx | 6.05 | High | block | 2026-08-04 |
| <fsssiedxi'sssiedx | 6.11 | High | review | 2026-08-04 |
| <fsssiedxa xx psssiedx | 4.45 | Medium | review | 2026-08-04 |
| <fsssiedxa$"sssiedx | 6.06 | High | review | 2026-08-04 |
| v3.69940/"();}]9994 | 6.18 | High | review | 2026-07-29 |
| v3.6"onmouseover=fTnz(98562)" | 6.05 | High | review | 2026-07-29 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 6.19 | High | review | 2026-07-29 |
| <%={{={@{#{${dfb}}%> | 4.50 | Medium | block | 2026-07-29 |
| dfb[[${98991*97996}]]xca | 6.12 | High | block | 2026-07-29 |
| dfb{{98991*97996}}xca | 6.39 | High | block | 2026-07-29 |
| v3.69566888< | 6.04 | High | block | 2026-07-29 |
| fsssiedx<sssiedx | 5.86 | Medium | review | 2026-07-28 |
| <fsssiedx{ xx psssiedx | 6.07 | High | block | 2026-07-28 |
| <fsssiedx{$"sssiedx | 6.11 | High | block | 2026-07-28 |
| <fsssiedxf'sssiedx | 6.07 | High | review | 2026-07-28 |
| fsssiedxxfdsaxax><!--></ScRiPt>asddsssiedx | 6.05 | High | review | 2026-07-28 |
| sssieddrubricxsx | 6.01 | High | block | 2026-07-28 |
| v3.6 | 4.45 | Medium | review | 2026-06-15 |
| v3.4-rev | 5.87 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 07:47
Listing SHA
9f9dd978f859…
Force block
— not fired
Score recovered
no
Elapsed
32.3s