Briskine: Email templates for Gmail™
lmcngpkjkplipamgflhioabnhnopeabf
Risk Score
4.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true: admits broad data sharing without scoping to this extension.
- Broad host permissions (https://*/*, http://*/*) with scripting allow content injection on every site visited.
- brand_mention.is_impersonation==true (LinkedIn mentioned) and developer_name is empty; not a verified publisher.
- Sandbox CSP contains unsafe-eval; DOM-XSS sink (innerHTML) present in content script on all pages.
- Uninstall URL hijack flagged; no developer name provided in listing.
Evidence
- privacy_policy_scope_mismatch api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy score per v3.5 rule D.
- broad_host_access manifest host_permissions include https://*/* and http://*/*; content_scripts also match both. Full site access.
- brand_impersonation store brand_mention.is_impersonation=true (LinkedIn), verified_publisher=false, is_featured_by_google=true → +1.0 reputation.
- dom_xss_sink crx innerHTML assigned from variable in content/content.js; CSP present but sandbox allows unsafe-eval.
- uninstall_url_hijack crx uninstall_url_hijack=true; uninstall_url_target=null. Triggers +3.0 webstore signal.
- no_developer_name store developer_name is empty string; +1.0 reputation penalty applied.
- featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount.
- sandbox_unsafe_eval manifest content_security_policy.sandbox includes unsafe-eval on script-src, elevating XSS risk in sandboxed context.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata across all open tabs.
- contextMenus low Adds items to right-click menu; low standalone risk.
- storage low Local data persistence for templates; expected for this category.
- scripting medium Can inject scripts into pages; medium risk, paired with broad host access.
- unlimitedStorage low Removes storage quota; low security risk but resource concern.
- https://*/* high Broad host access to all HTTPS sites enables content reading/injection.
- http://*/* high Broad host access to all HTTP sites; expands attack surface.
Pillar Scores
Permissions5.50
Reputation5.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA
e8b013acc454…
Force block
— not fired
Score recovered
no
Elapsed
24.7s