Page Locker
ldmnhdllijbchflpbmnlgndfnlgmkgif
Risk Score
4.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Free-webmail dev (gmail) with no developer name; verified-publisher discount applies but identity accountability low.
- scripting + <all_urls> + content_scripts on all URLs: full arbitrary code injection capability on every site.
- Privacy policy hosted on cloudapi.stream CDN (same domain as JS hosts); third_party_silence flag raised.
- 12 external JS hosts including raw.githubusercontent.com and bootstrap.gallery — broad remote dependency surface.
- small_install_high_perm anomaly: only 95 installs but full broad-host + scripting permissions.
Evidence
- free_webmail_dev_no_name store developer_email=viktornadiezhdin@gmail.com; developer_name empty; no verified business identity.
- verified_publisher store verified_publisher=true; reduces reputation risk but capped due to free-webmail identity.
- scripting_plus_all_urls manifest permissions=[scripting] + host_permissions=[<all_urls>] + content_scripts on <all_urls>; full code injection reach.
- external_js_hosts_12 crx 12 external JS hosts including raw.githubusercontent.com, bootstrap.gallery, cloudapi.stream; broad remote dep surface.
- privacy_policy_cdn_hosted store Privacy policy at cdn.cloudapi.stream; third_party_silence=true; policy fetched, scoped, but silence on 3rd-party sharing.
- dom_xss_sink crx innerHTML assignment from variable in daterange.js; DOM-XSS risk present without aggressive CSP on sandbox.
- sandbox_csp_unsafe_eval manifest Sandbox CSP allows unsafe-inline and unsafe-eval; mitigates extension_pages CSP hardening.
- install_perm_anomaly api 95 installs with high-tier permissions (scripting+<all_urls>); tail-attack-surface flag raised.
Permissions Breakdown
- storage low Local data persistence only.
- tabs medium Can read tab URLs and metadata across all tabs.
- webNavigation medium Monitors navigation events across all sites.
- sidePanel low UI surface only, low standalone risk.
- scripting high Can inject arbitrary scripts into pages; paired with <all_urls>.
- declarativeNetRequest medium Can block/redirect network requests declaratively.
- activeTab low Scoped to user-activated tab only.
- <all_urls> (host) high Grants access to every site; amplifies scripting and webNavigation.
- <all_urls> (content_scripts) high Content scripts injected on every page the user visits.
Pillar Scores
Permissions7.50
Reputation6.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:11
Listing SHA
8f89569b2e12…
Force block
— not fired
Score recovered
no
Elapsed
—