VIDAVA
kppmfkiklcbbjegkbmfnohoidobhgimj
Risk Score
3.74
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- <all_urls> host permission + content scripts on every page including checkout/payment pages handles sensitive financial data.
- Developer domain vidava.ai does not resolve — accountability gap for a financial AI extension.
- Privacy policy admits data collection and third-party sharing but lacks retention disclosure.
- innerHTML DOM sink in overlay JS is a XSS risk on pages where extension injects content.
- Very low install count (5) with HIGH-tier permissions is a tail-attack-surface anomaly.
Evidence
- host_permissions_all_urls manifest <all_urls> host permission combined with content_scripts on all URLs; runs on every site visited.
- developer_domain_not_resolving api threat_intel: vidava.ai domain does not resolve — no live accountability surface for developer.
- privacy_policy_no_retention api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- dom_xss_sink crx vidava-overlay.js: setBody(html){body.innerHTML=html} — unescaped variable into innerHTML, XSS risk.
- install_perm_anomaly store 5 installs with high-tier permission (<all_urls>); small_install_high_perm=true.
- js_external_hosts crx Extension contacts payjfhkpnsmyawugymfl.supabase.co, vidava.app, www.jsdelivr.com.
- no_csp manifest MV3 extension with csp_present=false; dom_sink_innerhtml_userctrl finding elevated by FIX B.
- unverified_new_developer store Not verified publisher, not featured, no ratings, domain non-resolving, 5 installs only.
Permissions Breakdown
- storage low Used to persist extension state locally; low standalone risk.
- activeTab medium Grants access to current tab on user action; scoped but pairs with <all_urls>.
- tabs medium Can read tab URLs and metadata across browser; moderate surveillance surface.
- <all_urls> (host_permission) high Content scripts injected on every site; reads checkout pages including payment data.
Pillar Scores
Permissions6.00
Reputation6.00
Network4.00
Webstore4.00
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:13
Listing SHA
0415da85ac1f…
Force block
— not fired
Score recovered
no
Elapsed
—