StayFocusd – Website Blocker & Focus Timer & Shorts Blocker
laankejkbhbdhmipfmgcngdelahlfoji
Risk Score
4.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy hosted on SensorTower (third-party analytics company), not scoped to this extension; admits data collection and third-party sharing.
- Broad content scripts injected on all URLs (*://*/*) gives extension reach into every page the user visits.
- Uninstall URL hijack flag is set — extension registers an uninstall URL pointing to unknown third-party destination.
- DOM-XSS sink (innerHTML) found in bundled JS without a CSP, increasing exploitability if attacker controls tooltip variable.
- No developer name listed; privacy policy domain (sensortower.com) does not match developer domain (stayfocusd.com), indicating policy may not be authoritative.
Evidence
- privacy_policy_not_scoped api Policy on sensortower.com: scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy (D rule).
- uninstall_url_hijack crx uninstall_url_hijack=true; target unknown. Webstore +3.0 applied.
- broad_content_scripts manifest content_scripts_matches includes *://*/* and http://*/* — injection on all URLs.
- dom_xss_sink_no_csp crx innerHTML userctrl sink in chunks/index-D-Dq_vpe.js; csp_present=false raises score to +2.0.
- description_permission_mismatch store Promises ad-blocking but lacks declarativeNetRequest/webRequest. +2.0 Webstore.
- no_developer_name store developer_name is empty string; +1.0 Reputation.
- featured_by_google store is_featured_by_google=true; -2.0 Reputation discount applied.
- js_external_hosts crx 12 external JS hosts including purchases.stayfreeapps.com, accounts.google.com, googleapis.com — >3 distinct domains.
Permissions Breakdown
- storage low Stores user blocking config locally; standard for productivity tools.
- tabs medium Can read tab URLs and titles; needed for blocking but grants broad URL visibility.
- alarms low Schedules focus timers; no sensitive data access.
- webNavigation medium Observes navigation events across all sites; needed for URL blocking enforcement.
- notifications low Displays focus alerts; no data exfil risk.
- identity medium OAuth token access; could expose Google identity. Scope unknown.
- content_scripts *://*/* high Broad content script injection on all URLs — matches stated blocking function but high reach.
Pillar Scores
Permissions3.80
Reputation5.50
Network1.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| v3.6 | 4.28 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.02 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA
04c6b733a359…
Force block
— not fired
Score recovered
no
Elapsed
25.5s