FastStream Video Player
kkeakohpadmbldjaiggikmnldlfkdfog
Risk Score
4.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- userScripts permission + <all_urls>: arbitrary script injection into every visited page is extremely high-capability.
- webRequest + <all_urls>: can observe/intercept all network traffic; amplifies risk of any future compromise.
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection & 3rd-party sharing.
- new Function() called with externally-supplied argNames/body in yt_runner.js; code-exec from message data.
- Free-webmail dev (gmail), no verified business identity, no developer name listed in store.
Evidence
- userScripts + <all_urls> manifest userScripts permission allows injecting arbitrary JS into all URLs; highest-risk capability combo in MV3.
- webRequest + <all_urls> manifest webRequest paired with broad host access enables full traffic interception across all sites.
- function_constructor in yt_runner.js crx new Function(event.data.argNames, event.data.body) executes attacker-controlled code from message events.
- generic privacy policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free-webmail developer, no name store Developer email andrews54757@gmail.com; developer_name empty; no verified business domain.
- verified_publisher + is_featured_by_google store Extension carries verified publisher and Featured badges — positive trust signal offsetting some reputation risk.
- no bad_host / affiliate / monetization hits api Threat intel shows zero bad hosts, affiliate hits, or monetization endpoints.
- CSP present, MV3, no obfuscation crx script-src 'self' wasm-unsafe-eval; no remote script loading; obfuscation_score=0.0.
Permissions Breakdown
- storage low Stores extension settings locally; standard low-risk API.
- tabs medium Can read tab URLs and titles across all tabs.
- webRequest high Intercepts all network requests; high capability when paired with <all_urls>.
- declarativeNetRequest medium Can block/redirect requests declaratively; scoped but still powerful.
- userScripts high Allows injecting arbitrary user scripts into pages; significant code-execution surface.
- <all_urls> (host_permission) high Grants content-script and request access to every URL the user visits.
Pillar Scores
Permissions6.50
Reputation5.00
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA
0abc459b41c8…
Force block
— not fired
Score recovered
no
Elapsed
23.8s