PDF Viewer
oemmndcbldboiebfnladdacbdfmadadm
Risk Score
3.55
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- webRequest + declarativeNetRequestWithHostAccess + <all_urls>: broad traffic interception capability on every site.
- 20 months since last update — stale for a high-reach extension with 1M installs.
- install_url_hijack flag set (target null): onInstalled behavior warrants manual verification.
- Developer name blank; identity relies solely on verified publisher badge and robwu.nl domain.
- Rating 3.3 may reflect user dissatisfaction; no review red-flags detected but context unknown.
Evidence
- verified_publisher + featured store Extension carries both verified publisher badge and is_featured_by_google; strong legitimacy signals.
- broad_permissions manifest webRequest + declarativeNetRequestWithHostAccess + <all_urls> justified for PDF proxy/intercept function.
- maintenance_stale store Last updated October 2024; 20 months since update triggers +6.0 maintenance score.
- install_url_hijack crx install_url_hijack=true but target=null; likely benign welcome page but flagged for review.
- code_quality_clean crx code_findings_raw empty, obfuscation_score 0.0, no CVEs, CSP present with strict self-only script-src.
- privacy_policy api Policy fetched, scoped to extension, no data collection declared, no third-party sharing; retention not stated.
- threat_intel_clean api No bad hosts, no affiliate hits, no monetization hits; developer domain robwu.nl resolves and not throwaway.
- operator_cluster api sibling_count=0; no related suspicious extensions under same fingerprint.
Permissions Breakdown
- alarms low Scheduling only; no data access.
- declarativeNetRequestWithHostAccess high Can intercept/redirect network requests across all URLs.
- webRequest high Observes all HTTP traffic; high data-exposure surface.
- tabs medium Access to tab URLs and metadata.
- webNavigation medium Monitors navigation events across all tabs.
- storage low Local extension data only.
- <all_urls> (host_permission) high Broad host access enables content script injection on every page.
- content_scripts file://*/* http://*/* https://*/* high Content scripts run on all pages; paired with <all_urls>.
Pillar Scores
Permissions5.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance6.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| %22fsssiedxa sssiedx | 3.27 | Low | review | 2026-08-13 |
| 'fsssiedxa$'sssiedx | 3.17 | Low | review | 2026-08-13 |
| fsssiedxa<sssiedx | 3.13 | Low | review | 2026-08-13 |
| <fsssiedxi xx psssiedx | 3.38 | Low | review | 2026-08-11 |
| <fsssiedxi'sssiedx | 3.10 | Low | review | 2026-08-11 |
| <fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 3.01 | Low | review | 2026-08-11 |
| <fsssiedxa'sssiedx | 3.14 | Low | review | 2026-08-11 |
| fsssiedx<sssiedx | 2.96 | Low | review | 2026-08-11 |
| sssieddrubricxsx | 3.17 | Low | review | 2026-07-31 |
| v3.6 | 3.55 | Low | allow | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA
0305270b7fb6…
Force block
— not fired
Score recovered
no
Elapsed
22.5s