Save Story for Instagram
lknpbgnookklokdjomiildnlalffjmma
Risk Score
4.58
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Gmail dev email + free hosting privacy policy + Instagram brand impersonation raises unverifiable identity risk.
- scripting + <all_urls> content_scripts grants arbitrary JS injection on every site visited, not just Instagram.
- new Function() constructor in bg.js enables dynamic code execution from potentially user/network-controlled input.
- Privacy policy on Google Sites lacks retention disclosure and third-party sharing silence is unresolved.
- Instagram brand mention with unconfirmed ownership (confirmed_owner=false) meets impersonation criteria.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer is gmail user, not Meta/Instagram.
- free_webmail_dev store developer_email=lisap6237@gmail.com; free-webmail with no verified business domain.
- broad_host_access manifest host_permissions=[<all_urls>] + content_scripts_matches=[<all_urls>]; scope far exceeds instagram.com.
- function_constructor crx new Function() in js/bg.js allows dynamic code execution; risky with <all_urls> content access.
- privacy_policy_gaps api Policy on sites.google.com; scope_extension=true, data_collection=true, retention=false, third_party_silence=true.
- featured_by_google store is_featured_by_google=true provides partial legitimacy signal despite other risk factors.
- js_external_hosts crx References popper.js.org, sweetalert2.github.io, stuk.github.io, www.facebook.com, www.instagram.com.
- no_csp manifest content_security_policy=null on MV3; MV3 provides strict default but no custom CSP declared.
Permissions Breakdown
- system.display low Read display configuration; low standalone risk.
- declarativeNetRequest medium Can block/modify network requests; paired with <all_urls> increases risk.
- downloads medium Initiates file downloads; core to stated function but abusable.
- scripting high Injects scripts into pages; combined with <all_urls> gives broad code execution.
- storage low Local extension data storage; low risk alone.
- tabs medium Can read tab URLs and navigate; moderate privacy surface.
- <all_urls> (host_permission) high Content scripts + scripting on all URLs; broad access beyond Instagram alone.
Pillar Scores
Permissions6.50
Reputation7.00
Network2.00
Webstore5.50
Maintenance0.00
Privacy2.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| sssiedna83e552bdp727562726963xsx | 4.05 | Medium | review | 2026-09-10 |
| v3.6 | 4.58 | Medium | review | 2026-08-28 |
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:56
Listing SHA
f128e71c09da…
Force block
— not fired
Score recovered
no
Elapsed
—