Bookmark Manager and Viewer
mnhojcjhcilkgkmijhphlbmghmmdhlfg
Risk Score
4.31
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy (scope_extension=false, admits data collection & 3rd-party sharing) — scores maximum privacy risk.
- Developer uses free Gmail address (inb.cor@gmail.com) with no verified business domain — low accountability.
- Install URL hijack detected: onInstalled opens internal page — minor but flags monetization/tracking pattern.
- Uninstall URL hijack flag set — combined with install hijack raises shell-pattern concern despite no external target confirmed.
- Geo-diverse JS hosts (CA/IN/NL/US, 4 countries) and 12 external JS hosts listed in fingerprint — broad external surface for a bookmark tool.
Evidence
- privacy_policy_generic_google store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension. scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_gmail_no_domain store Developer email inb.cor@gmail.com; brand_mention.developer_domain=gmail.com; no business domain registered.
- install_url_hijack crx install_url_hijack=true; target=/data/panel/index.html?in=tab (internal, not 3rd-party).
- uninstall_url_hijack crx uninstall_url_hijack=true; uninstall_url_target=null — target unresolved, rule triggered.
- host_geo_diversity crx JS hosts span 4 countries (CA, IN, NL, US); 12 distinct external JS hosts in operator fingerprint.
- dom_sink_innerhtml crx jquery-3.7.1.js contains innerHTML assignment from variable; no CSP present — DOM-XSS risk elevated.
- featured_by_google store is_featured_by_google=true — partial trust signal, mitigates but does not eliminate reputation concerns.
- no_cve_findings crx cve_findings_raw empty; jquery 3.7.1 has no known CVEs in OSV scan. CVE pillar=0.
Permissions Breakdown
- storage low Stores extension settings/bookmark data locally. Expected for this category.
- activeTab low Accesses current tab on user gesture only. Limited scope.
- bookmarks medium Full read/write access to all user bookmarks — core function but sensitive data.
- favicon low Fetches site favicons for display. Low-risk.
- notifications low Desktop notifications without host access. Low standalone risk.
- contextMenus low Adds right-click menu items. Low risk.
- declarativeContent low Matches page conditions to show extension UI. No content read.
Pillar Scores
Permissions2.30
Reputation6.50
Network3.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA
23cab8f2423e…
Force block
— not fired
Score recovered
no
Elapsed
25.7s