Poster Print
lklpgnoakidgmajbkachidckmhjjdage
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- declarativeNetRequestWithHostAccess + <all_urls> allows network-level interception on every site.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- Free-webmail developer (gmail) with no verified business identity; low accountability.
- install_url_hijack flagged: extension opens a URL on install to unknown 3rd-party target.
- 9 external JS hosts including lambda AWS endpoint and www.mellow.tel; suspicious for a simple poster-print tool.
Evidence
- declarativeNetRequestWithHostAccess + <all_urls> manifest HIGH permission combo: can rewrite/block any request on any URL. Scope mismatch with stated image-splitting function.
- install_url_hijack crx install_url_hijack=true; extension opens 3rd-party URL on install. Target not disclosed.
- Generic Google privacy policy store Policy is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true). Not scoped to extension.
- Free-webmail developer, no verified publisher store Developer email ranielhy@gmail.com; not verified publisher; no business domain.
- 9 external JS hosts crx Includes aws lambda URL, www.mellow.tel, aim.cloudflare.com — anomalous for a poster-printing utility.
- small_install_high_perm anomaly api Only 20 installs but HIGH-tier permissions (declarativeNetRequestWithHostAccess + all_urls).
- No CSP (MV3) manifest csp_present=false; MV3 has strict default but absence noted with external hosts.
- Content scripts injected on all URLs manifest content_scripts_matches=[<all_urls>]: JS runs on every page the user visits.
Permissions Breakdown
- storage low Standard local data persistence; low standalone risk.
- declarativeNetRequestWithHostAccess high HIGH perm: can intercept/block/redirect network requests on all URLs.
- <all_urls> (host_permissions) high Grants access to every site the user visits; broad reach.
- content_scripts <all_urls> high Injects JS into every page; combined with broad host access is high risk.
Pillar Scores
Permissions7.50
Reputation6.50
Network6.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 13:24
Listing SHA
6e99b0fec4e5…
Force block
— not fired
Score recovered
no
Elapsed
—