Black Script
lmenhcepphonnfnjkaofobpamlfolgfl
Risk Score
4.63
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — does not scope to this extension, admits data collection and third-party sharing (privacy pillar capped at 10).
- Free-webmail developer (qsakaro@gmail.com) with no developer name or verified identity — elevated reputation risk.
- Extension contacts external hosts (example.com, forms.gle, t.me) with no CSP; destination purpose unclear.
- Very low install base (104) with external JS hosts creates a tail attack surface if extension is ever compromised.
- No developer name provided, raising accountability concerns for enterprise deployment.
Evidence
- generic_privacy_policy store Privacy policy URL is Google's own policy; scope_extension=false, data_collection=true, third_party_sharing=true — maps to +10 Privacy per v3.5 rule D.
- free_webmail_no_dev_name store Developer email qsakaro@gmail.com; developer_name is empty. Reputation start 5 +1.5 (free webmail, no biz site) +1.0 (no dev name) = 7.5 floor applied.
- external_js_hosts crx js_external_hosts: example.com, forms.gle, t.me — 3 distinct domains referenced from JS; no CSP present.
- narrow_content_script manifest Content script scoped only to https://forum.blackrussia.online/* — single-site forum helper, low capability.
- no_csp_mv3 manifest csp_present=false; MV3 default is strict, so no +2 Network penalty applies, but no mitigating CSP either.
- no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; jquery 3.7.1 bundled (no known CVEs).
- low_install_count store 104 installs; not a broad-reach risk but limits trust signals.
- no_bad_hosts_no_monetization api threat_intel.bad_host_hits, monetization_hits, affiliate_hits all empty; no threat-intel risk amplifiers.
Permissions Breakdown
- storage low Stores local settings; no cross-site or data-exfil capability on its own.
- content_scripts: https://forum.blackrussia.online/* medium Runs JS on a single specific forum domain; narrow but grants DOM access on that origin.
Pillar Scores
Permissions1.00
Reputation7.50
Network0.00
Webstore10.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:18
Listing SHA
32b369ce9b51…
Force block
— not fired
Score recovered
no
Elapsed
—