Relay Developer Tools
ncedobpgnmkhcmnnkcimnobpfepidadl
Risk Score
3.54
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does NOT scope to this extension; data_collection+third_party_sharing admitted without extension-specific disclosure.
- Content scripts injected on <all_urls> with scripting permission gives broad cross-origin code execution capability on every site.
- 16 months since last update elevates risk of unpatched issues; falls in 12-24mo stale band.
- Dynamic script injection (script_src_dynamic) and innerHTML sink (dom_sink_innerhtml_userctrl) detected in bundled JS.
- Developer listed as Meta but verified_publisher=false; privacy policy links to Google account policy, not Meta/FB policy.
Evidence
- broad_host_access manifest host_permissions=[<all_urls>] and content_scripts_matches=[<all_urls>]; scripting on every site.
- generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — Google account policy, scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store Last updated Feb 4 2025; 16 months since update — 12-24mo stale band (+6.0 maintenance).
- code_dynamic_script crx script_src_dynamic in injectGlobalHook.js: createElement('script').src=chrome.runtime.getURL(...).
- code_innerhtml_sink crx dom_sink_innerhtml_userctrl in main.js; CSP present mitigates XSS risk but sink remains.
- unverified_publisher store Developer claims Meta/extensions@fb.com but verified_publisher=false; no recognition discount applied.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 6000 installs with HIGH-tier permissions.
- js_external_hosts crx 3 external JS hosts referenced: bugs.chromium.org, fb.me, reactjs.org (likely docs/links, not script loads).
Permissions Breakdown
- webNavigation medium Allows monitoring all navigation events; paired with <all_urls> increases reach.
- scripting high Enables programmatic script injection into pages; HIGH capability when combined with <all_urls>.
- <all_urls> (host_permission) high Broad host access to every site; amplifies scripting and content_script reach.
- content_scripts <all_urls> high Auto-injected into every page, extends scripting surface to all origins.
Pillar Scores
Permissions5.50
Reputation4.50
Network1.50
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality3.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA
e7fad30a9f61…
Force block
— not fired
Score recovered
no
Elapsed
25.6s