Apple Music(iTunes) Web Player
lmnnbjniocahgmdmhgpbfdapbelhjnil
Risk Score
4.14
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Search provider hijack: routes all searches to chromecrxstore.com while branding itself 'Google Search'.
- Apple brand impersonation by unverified gmail developer — no confirmed ownership of Apple trademarks.
- Privacy policy URL returns fetch error; policy is effectively absent — score treated as unfetched.
- Free-webmail developer (js8231437@gmail.com) with no verifiable business identity.
- Extension title/description promises Apple Music playback but delivers only a search redirect.
Evidence
- search_provider_override manifest chrome_settings_overrides.search_provider redirects to chromecrxstore.com/query/ with is_default=true, named 'Google'.
- brand_impersonation store brand_mention.is_impersonation=true; Apple brand used; developer is gmail account with no Apple affiliation.
- privacy_policy_fetch_error api privacy_policy_classification.fetched=false reason=fetch_error:HTTPError; policy treated as absent.
- free_webmail_developer store Developer email js8231437@gmail.com; no business domain; no verified publisher badge.
- external_js_host crx js_external_hosts=[chromecrxstore.com] — same domain as search redirect and broken privacy policy.
- maintenance_stale store months_since_update=12; falls in 6-12mo band (+3.5).
- no_csp manifest content_security_policy=null; MV3 default CSP applies but no explicit policy declared.
- description_mismatch store Title promises Apple Music/iTunes web player; actual function is search provider override to chromecrxstore.com.
Permissions Breakdown
- chrome_settings_overrides.search_provider medium Overrides default search to chromecrxstore.com masquerading as Google — search hijack.
Pillar Scores
Permissions3.00
Reputation8.50
Network2.00
Webstore7.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-02 15:52
Listing SHA
a931f02218e0…
Force block
— not fired
Score recovered
no
Elapsed
—