GPTZero: AI Detection & Writing Replay
kgobeoibakoahbfnlficpmibdbkdchap
Risk Score
5.49
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true — admits broad data sharing without scoping to extension (v3.5 D: +10.0 privacy).
- Content scripts on <all_urls> combined with cookies permission enables reading page content and session cookies across all sites including Google Docs and ChatGPT.
- 10 innerHTML DOM-XSS sinks across multiple content-script files with no CSP; elevated DOM-XSS risk per FIX B.
- brand_mention.is_impersonation=true (mentions Google brand) without verified_publisher — reputation penalty applied.
- Uninstall URL hijack detected (uninstall_url_hijack=true); third-party destination unconfirmed — webstore penalty applied.
Evidence
- privacy_policy_scope_extension_false_with_data_and_third_party_sharing api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
- content_scripts_all_urls_plus_cookies manifest content_scripts matches <all_urls>; cookies permission allows reading cookies on all host_permission domains.
- dom_sink_innerhtml_no_csp crx 10 innerHTML sinks across content scripts; csp_present=false triggers FIX B elevated scoring (+2.0 code quality).
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() to third-party target detected; +3.0 webstore penalty.
- brand_impersonation_google store brand_mention.is_impersonation=true, Google mentioned; not verified_publisher, not featured for this signal.
- ai_extension_page_content store AI detection category processing page content on Google Docs/ChatGPT; +2.5 webstore AI signal.
- no_csp_mv3 manifest content_security_policy=null on MV3; MV3 strict default applies, no +2.0 network penalty for missing CSP.
- is_featured_by_google store Extension carries Google Featured badge; -2.0 reputation discount applied.
Permissions Breakdown
- scripting medium Can inject scripts into pages; broad reach given content_scripts on <all_urls>.
- cookies high Access to cookies across host_permissions scope including Google Docs, ChatGPT.
- storage low Local extension storage only.
- contextMenus low Adds right-click menu items; low standalone risk.
- tabs medium Can read tab URLs and titles across browser.
- alarms low Scheduled background tasks; low risk alone.
- host:<all_urls> (content_scripts) high Content scripts run on all URLs — broad page-content read access.
- host:https://*.gptzero.me/* low Developer's own domain; expected for AI detection service.
- host:https://docs.google.com/* medium Access to Google Docs content — sensitive documents.
- host:https://chatgpt.com/* medium Access to ChatGPT sessions and conversation content.
- host:https://*.growthbook.io/* medium Third-party A/B testing/feature-flag service; data may flow externally.
- host:http://localhost/* low Localhost access; likely dev/staging only.
Pillar Scores
Permissions6.50
Reputation5.50
Network4.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA
951d9e0bd5f8…
Force block
— not fired
Score recovered
no
Elapsed
36.2s