Default zoom for Google Workspace
nflkcdlimipkgbacnfnhfecjgmojhklo
Risk Score
4.59
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: title/description mentions 'Google' and 'Zoom' but developer is unverified gmail user.
- Privacy policy is Google's generic account policy — not scoped to this extension; data practices undisclosed.
- No CSP + 3x innerHTML sinks across JS files raise DOM-XSS risk on Google Workspace pages.
- Gmail developer with no verified business domain; identity unverifiable.
- 17 months since last update — approaching stale threshold with no disclosed changelog.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; mentions google+zoom; developer is unverified gmail user, not confirmed owner.
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's account policy, scope_extension=false, collects+shares data.
- no_csp crx csp_present=false, MV3; no content_security_policy declared.
- innerHTML_sinks crx 3 files contain dom_sink_innerhtml_userctrl; no CSP present amplifies DOM-XSS risk per FIX B.
- free_webmail_developer store developer_email=alvernacchia@gmail.com; no business domain; domain_age_ct not queried (free webmail).
- maintenance_stale store months_since_update=17; falls in 12-24mo band (+6.0 maintenance score).
- is_featured_by_google store Extension carries Google Featured badge, provides partial reputation mitigation.
- no_bad_hosts_no_affiliate crx threat_intel bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no malicious network indicators.
Permissions Breakdown
- storage low Stores extension settings locally; low risk, standard for zoom/preference extensions.
- http://*.google.com/ (host_permission) medium Broad Google domain access enables content script injection on all Google subdomains.
Pillar Scores
Permissions1.30
Reputation7.50
Network0.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA
1ad0e26b6a24…
Force block
— not fired
Score recovered
no
Elapsed
25.5s