MediaPlayer - Video and Audio Player
mgmhnaapafpejpkhdhijgkljhpcpecpj
Risk Score
5.43
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy (scope_extension=false, admits data_collection+third_party_sharing) → +10.0 privacy pillar
- Install URL hijack (onInstalled opens internal /data/styling/index.html) and uninstall URL hijack flag both set — monetization/tracking shell pattern
- Developer uses free webmail (gmail) with no business domain; domain_age_ct not queryable; elevated identity risk
- declarativeNetRequestWithHostAccess can silently redirect or block network requests; no CSP adds surface
- 12 external JS hosts referenced including ad/analytics-adjacent domains; MV3 no-CSP adds +2.0 network risk
Evidence
- install_url_hijack crx install_url_hijack=true targeting /data/styling/index.html; onInstalled fires redirect on every install.
- uninstall_url_hijack crx uninstall_url_hijack=true; target null but flag set — likely survey/ad redirect pattern.
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email inb.cor@gmail.com; brand_mention.developer_domain=gmail.com; no business website.
- declarativeNetRequestWithHostAccess manifest HIGH-tier permission enabling network request redirect/blocking without visible host_permissions declared.
- js_external_hosts_count crx 12 distinct external hosts in JS files including webbrowsertools.com, brightcove.com; country_count=1 (IN).
- no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit restriction declared.
- is_featured_by_google store Extension carries Google Featured badge, providing partial reputation credit.
Permissions Breakdown
- storage low Stores local preferences; low standalone risk.
- contextMenus low Adds right-click menu items; low risk.
- notifications low Can push desktop notifications; minor annoyance risk.
- declarativeNetRequestWithHostAccess high Can redirect/block network requests; broad capability without host_permissions still significant.
Pillar Scores
Permissions3.50
Reputation7.00
Network3.50
Webstore7.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA
cbbe8f34da73…
Force block
— not fired
Score recovered
no
Elapsed
21.6s