Codecode Review for GitLab
npinjojmpfjohjckpnldackfhlflmhaj
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: mentions 'gitlab' but dev is free-webmail gmail with no verified relationship.
- Privacy policy is Google's own generic policy — scope_extension=false, data_collection=true, third_party_sharing=true; admits data sharing without scoping to this extension.
- Content script runs on https://*/*, far broader than stated GitLab-only function.
- Uninstall URL hijack detected; redirects user on removal to unknown destination.
- Developer contacts personal unknown domain (jevgenij.eu) and Google Analytics with no disclosed purpose.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands=['gitlab']; dev domain=gmail.com; confirmed_owner=false.
- free_webmail_dev store Developer email supergitlabcodereview@gmail.com; no business website; throwaway-style username.
- generic_google_privacy_policy store Privacy URL points to myaccount.google.com; scope_extension=false, data_collection=true, third_party_sharing=true.
- content_script_overbroad manifest content_scripts_matches=['https://*/*'] but extension claims only GitLab functionality.
- uninstall_url_hijack crx uninstall_url_hijack=true; target not disclosed; 3.0 Webstore penalty applied.
- external_host_personal_domain crx js_external_hosts includes jevgenij.eu (personal EU domain) and gitlab.jaumo.com; not explained.
- monetization_hit crx threat_intel.monetization_hits: www.google-analytics.com (telemetry); telemetry-tier only.
- no_csp manifest content_security_policy=null on MV3; no additional amplifier but raises injection risk.
Permissions Breakdown
- storage low Standard local storage for settings/state.
- alarms low Scheduled tasks; minimal standalone risk.
- notifications low Desktop notifications; low capability risk.
- host: https://jevgenij.eu/* medium Scoped to unknown personal domain; unclear data flow.
- host: https://www.google-analytics.com/* medium Telemetry to GA; behavior tracking of unknown scope.
- content_scripts: https://*/* high Runs JS on every HTTPS page; broad DOM access beyond stated GitLab scope.
Pillar Scores
Permissions4.50
Reputation8.50
Network4.00
Webstore7.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA
5d9effc609fb…
Force block
— not fired
Score recovered
no
Elapsed
22.2s