Browser Security Plus
mhkgegcmcapcgmnnloigolapjkajgfmd
Risk Score
6.64
Risk Level:
High
Recommendation:
🚫 BLOCK
FORCE-BLOCK
Top Risks
- FORCE BLOCK: management + broad host access — extension can disable security tools AND has full traffic-routing capability.
- CRITICAL permission stack: management + nativeMessaging + contentSettings + webRequest + scripting + <all_urls> — complete browser control with unrecognized native host.
- Privacy policy admits data collection and third-party sharing but is NOT scoped to this extension — D clause triggers +10.0 privacy score.
- Brand impersonation flag: brand_mention.is_impersonation==true for 'google' while developer is not verified owner — reputation penalty applied.
- No developer name listed; rating of 1.6 on 1M installs is a strong negative quality signal.
Evidence
- high_permission_stack manifest management, nativeMessaging, webRequest, privacy, contentSettings, scripting all declared with <all_urls> host permission.
- native_messaging_unrecognized_publisher crx has_native_messaging=true, publisher_recognized=false → +3.0 permissions per rule (15).
- privacy_policy_generic_with_sharing api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- brand_impersonation store brand_mention.is_impersonation=true for 'google'; confirmed_owner=false; not verified_publisher → +2.0 reputation.
- low_rating_high_installs store Rating 1.6 on 1,000,000 installs is a strong negative signal; +1.0 reputation if >= 50 ratings assumed.
- dom_xss_sink_no_csp crx innerHTML from variable in contentScript.js; csp_present=false triggers FIX B escalation to +2.0 code quality.
- no_developer_name store developer_name is empty string; partial +1.0 reputation penalty for missing 'Offered by' identity.
- verified_publisher_present store verified_publisher=true applies -3.0 reputation discount; 0c cap not triggered (domain resolves, no CVEs, months_since_update=0, no monetization hits).
Permissions Breakdown
- management high Can enumerate, enable/disable, or uninstall other extensions — extreme capability.
- webRequest high Can observe all HTTP/S traffic across all URLs (paired with <all_urls>).
- nativeMessaging high Bridges to a native host app; publisher_recognized==false amplifies risk.
- privacy high Can read/write browser privacy settings (network prediction, safe browsing, etc.).
- contentSettings high Can override per-site cookie, JS, camera, mic, and plugin permissions.
- downloads medium Can initiate and monitor file downloads.
- scripting high Programmatic script injection into any page via <all_urls> host permission.
- tabs medium Access to tab URLs, titles, and navigation state.
- webNavigation medium Monitors all navigation events across all URLs.
- <all_urls> (host) high Broad host access amplifies every HIGH permission by ×1.2.
Pillar Scores
Permissions8.50
Reputation5.50
Network2.00
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| v3.6 | 6.64 | High | block | 2026-06-16 |
| v3.4-rev | 5.55 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA
e2c55a088f46…
Force block
🚫 fired
Score recovered
no
Elapsed
29.2s