Offline QR Code Generator/Editor
kfhbhjigpkcbpmknfomdobahejfajado
Risk Score
5.72
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Content script injected on <all_urls> gives broad DOM read/write access to every page visited.
- Abandoned for 54 months — high risk of unpatched vulnerabilities or future hostile takeover.
- Privacy policy is Google's own policy, not scoped to this extension; data practices undisclosed.
- Developer name is a third-party download site URL (weibomiaopai.com), not a verified identity.
- innerHTML DOM-XSS sink in contentscript.js with no CSP; exploitable if input is attacker-controlled.
Evidence
- content_scripts_matches=<all_urls> manifest Content script runs on every URL — high REACH despite low declared permissions.
- months_since_update=54 store Last updated December 2021; over 4 years stale — maintenance score 10.0.
- privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_identity store Developer name is a weibomiaopai.com URL; email is free Gmail. No verified publisher badge.
- dom_sink_innerhtml_userctrl crx innerHTML used in contentscript.js with no CSP present — DOM-XSS risk.
- csp_present=false manifest No content_security_policy declared; MV3 strict default applies but no explicit hardening.
- is_featured_by_google=true store Extension carries Google Featured badge, providing partial reputation credit.
- js_external_hosts=[chart.googleapis.com] crx Single external host is Google Charts API — low threat-intel risk, no bad-host hits.
Permissions Breakdown
- activeTab low Scoped to user-initiated action on current tab only.
- storage low Local data persistence; no exfil risk on its own.
- contextMenus low Adds right-click menu items; low standalone risk.
- content_scripts:<all_urls> high Content script injected on ALL URLs — broad DOM access across every site visited.
Pillar Scores
Permissions4.50
Reputation7.50
Network2.00
Webstore2.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA
9c0e6f7050fa…
Force block
— not fired
Score recovered
no
Elapsed
22.8s