Netflix Party
mmnbenehknklpbendgmgngeaignppnbe
Risk Score
6.09
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Brand impersonation: unverified Gmail dev claims Netflix name with confirmed_owner=false.
- Privacy policy is Google's own generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Broad host access (*://*/*) + scripting permission lets extension read/modify every site the user visits.
- External JS host 'all.telenetflixparty.com' is a non-Netflix domain suggesting parallel infrastructure; dev is Gmail-only.
- Free-webmail developer (customfb8@gmail.com), no verified publisher, no business domain — high abandonment/sale risk.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; dev is customfb8@gmail.com, confirmed_owner=false, not verified publisher.
- generic_privacy_policy store Privacy URL is Google's own policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true.
- broad_host_access manifest host_permissions=[*://*/*] + content_scripts on <all_urls> + scripting permission = full read/write on every page.
- external_non_netflix_host crx js_external_hosts includes all.telenetflixparty.com — unrelated domain controlled by unknown party.
- free_webmail_developer store Developer email customfb8@gmail.com with numbered alias pattern; no business website or verified publisher badge.
- dom_xss_sinks crx innerHTML assignments in popup.js and content.js with no CSP; elevated DOM-XSS risk on all visited pages.
- csp_absent manifest content_security_policy=null; MV3 default applies but no explicit CSP hardening declared.
- multi_platform_host_access crx External hosts include netflix.com, youtube.com, primevideo.com, jiocinema.com — far beyond stated Netflix Party scope.
Permissions Breakdown
- tabs medium Access to tab URLs and metadata; moderate risk alone but amplified by broad host access.
- storage low Local data persistence; low standalone risk.
- scripting high Programmatic script injection into pages; high risk paired with *://*/* host access.
- *://*/* high Broad host access — extension can read/modify every site visited by the user.
- <all_urls> (content_scripts) high Content scripts injected into all URLs — maximum reach for a party-watch tool.
Pillar Scores
Permissions7.20
Reputation9.00
Network4.00
Webstore7.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:45
Listing SHA
a105db17c301…
Force block
— not fired
Score recovered
no
Elapsed
—