Simplified Twitter/X
kfopmjhmejbgomgeajemgpgpbckpoopg
Risk Score
4.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy — does not scope to this extension; admits data collection and third-party sharing.
- brand_mention flags 'twitter' as impersonation; developer not confirmed owner, not verified publisher.
- Dynamic script injection (script_src_dynamic) in inject.js with no CSP; injects bundled script.js into Twitter/X pages.
- No CSP defined (MV3 default applies but no explicit restriction); dynamic script tag creation increases attack surface.
- Last updated 11 months ago; moderate staleness with scripting capability on high-value social platform.
Evidence
- privacy_policy_generic store Policy URL is Google's account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true — D clause applies: +10.0.
- brand_impersonation store brand_mention.is_impersonation=true for 'twitter'; confirmed_owner=false; not verified_publisher or featured: +2.0 reputation.
- script_src_dynamic crx inject.js creates <script src=runtime.getURL('script.js')>; internal URL only, no external loading detected.
- no_csp manifest content_security_policy is null; MV3 strict default applies but no explicit policy declared.
- host_permissions_scoped manifest host_permissions limited to x.com, twitter.com, mobile.twitter.com — consistent with stated Twitter/X simplifier function.
- no_bad_hosts_no_affiliates api threat_intel shows no bad_host_hits, affiliate_hits, or monetization_hits. js_external_hosts empty.
- maintenance_staleness store 11 months since last update; falls in 6-12mo band: +3.5.
- operator_cluster_clean api sibling_count=0; no related extensions under same fingerprint.
Permissions Breakdown
- scripting medium Allows dynamic script injection; scoped to twitter/x.com only via host_permissions.
- https://x.com/* medium Host access scoped narrowly to Twitter/X domains only.
- https://twitter.com/* medium Host access scoped narrowly to Twitter/X domains only.
- https://mobile.twitter.com/* low Narrow mobile sub-domain scope consistent with stated function.
Pillar Scores
Permissions2.00
Reputation6.00
Network0.00
Webstore2.00
Maintenance3.50
Privacy10.00
Code Quality3.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA
15d93f24a102…
Force block
— not fired
Score recovered
no
Elapsed
22.6s