Stylebot
oiaejidbmkiecgbjeifoejpgmdaleoha
Risk Score
4.03
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- content_scripts on <all_urls> gives read/write DOM access across every site visited.
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- eval() and new Function() in bundled RequireJS and multiple entry points without CSP protection.
- Developer uses free Gmail address; no verified business domain for accountability.
- Last updated ~13 months ago; stale for a widely-installed (200K) CSS-injection tool.
Evidence
- content_scripts_all_urls manifest content_scripts matches <all_urls> — injects into every page the user visits.
- generic_privacy_policy store Privacy policy is Google's account policy (myaccount.google.com); scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
- eval_in_requirejs crx eval_user_input in monaco-editor/iframe/node_modules/requirejs/require.js; no CSP to mitigate.
- function_constructor_multi_files crx new Function() found in editor, inject-css, options, popup, readability, sync entry points.
- gmail_developer store Developer email ahuja.ankit@gmail.com; free webmail, no business domain resolved.
- no_csp manifest content_security_policy is null (MV3 default strict CSP applies, but no explicit extension CSP declared).
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; mitigates reputation concern.
- stale_13mo store Last updated May 2024 (~13 months); 200K installs with no recent update is a supply-chain risk.
Permissions Breakdown
- tabs medium Access to tab URLs/titles; needed for CSS injection per-site.
- storage low Stores user CSS styles locally.
- identity low OAuth token for Google Drive sync; no broad scopes declared.
- contextMenus low Adds right-click menu items; low standalone risk.
- unlimitedStorage low Allows large CSS/style storage; no data-exfil risk alone.
- content_scripts <all_urls> high Injects scripts into every page; high REACH for a CSS editor.
- host_permissions: drive.google.com, googleapis.com, fonts.googleapis.com medium Scoped to Google APIs for Drive sync and font loading; narrow but sensitive.
Pillar Scores
Permissions4.00
Reputation3.50
Network2.00
Webstore1.50
Maintenance3.50
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 14:33
Listing SHA
a47c65655322…
Force block
— not fired
Score recovered
no
Elapsed
29.5s