Open in PDF Reader
kdpmhmcieiaddjoegooocahccoegbemo
Risk Score
7.07
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- nativeMessaging with unrecognized publisher — grants full OS-level code execution to unknown companion app.
- Extension abandoned for 47 months; no security patches since July 2022.
- Privacy policy is Google's generic policy — does not scope to this extension at all (data_collection+third_party_sharing admitted, scope_extension==false → +10.0).
- Free-webmail developer (gmail), no developer name, no business website — identity unverifiable.
- install_url_hijack and uninstall_url_hijack both flagged; install/uninstall hooks present.
Evidence
- nativeMessaging_unrecognized_publisher manifest native_messaging_check: has_native_messaging=true, publisher_recognized=false → +3.0 Permissions.
- abandoned_extension store last_updated July 2022, months_since_update=47 (>36mo) → Maintenance +10.0.
- generic_google_privacy_policy store Privacy policy is myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0.
- free_webmail_no_dev_name store developer_email=arsalan.sosa2021@gmail.com, developer_name empty, no business domain → Reputation floor >=7.5.
- install_uninstall_url_hijack crx install_url_hijack=true, uninstall_url_hijack=true. Targets null (could not resolve) — monetization shell signal.
- dom_sink_innerhtml_userctrl_no_csp crx innerHTML sink in js/common.js with csp_present=false → Code Quality +2.0 (FIX B).
- function_constructor_in_pdfjs crx new Function() in pdf.min.js and pdf.worker.min.js → Code Quality +2.5.
- verified_publisher_cap_applied store verified_publisher=true but months_since_update=47>18 → 0c cap: discount capped at -1.0 on Reputation.
Permissions Breakdown
- storage low Stores extension settings locally; low risk.
- downloads medium Can initiate and manage file downloads; moderate risk.
- contextMenus low Adds right-click menu items; low risk.
- nativeMessaging high Communicates with unrecognized native app — full system escape, publisher not recognized.
Pillar Scores
Permissions7.00
Reputation7.50
Network0.00
Webstore6.50
Maintenance10.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA
842518919a00…
Force block
— not fired
Score recovered
no
Elapsed
25.4s