Netflix with Elapsed Time
knglmjodeneocikihhehegeifgabkjfa
Risk Score
4.26
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Netflix brand impersonation by unverified gmail developer — no confirmed ownership.
- Privacy policy is Google's generic policy (scope_extension=false, admits data collection and 3rd-party sharing) — scores maximum privacy risk.
- install_url_hijack=true: onInstalled opens a third-party URL.
- DOM-XSS sink (innerHTML with variable) in vendor/overlay-widget.js could enable content injection on Netflix.
- Free-webmail developer with no business domain; identity unverifiable.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'netflix'; developer is unverified gmail user.
- install_url_hijack crx install_url_hijack=true; target=null. Opens 3rd-party URL on install.
- generic_privacy_policy api Policy is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true.
- dom_xss_sink crx vendor/overlay-widget.js: innerHTML assigned from variable — DOM-XSS risk on netflix.com.
- free_webmail_developer store Developer email mynjcolo@gmail.com; no business domain; identity unverifiable.
- external_hosts crx JS contacts fonts.googleapis.com, ko-fi.com, storage.ko-fi.com — donation widget, low risk.
- csp_present_mv3 manifest CSP script-src 'self'; object-src 'self' — strict, no remote script loading.
- no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.
Permissions Breakdown
- storage low Stores local extension state; no cross-origin data exposure.
- tabs medium Can read tab URLs/titles; moderate info exposure.
- host:https://www.netflix.com/* medium Scoped to Netflix only; content script injection on a major platform.
Pillar Scores
Permissions2.00
Reputation7.50
Network0.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA
b487da6bc318…
Force block
— not fired
Score recovered
no
Elapsed
21.6s