Netflix Party is now Teleparty
oocalimimngaihdkbihfgmpkcpnmlaoa
Risk Score
3.74
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false + data_collection=true + third_party_sharing=true → admits broad data sharing without extension-specific scoping.
- Brand impersonation flag: 'netflix' mentioned, confirmed_owner=false, is_impersonation=true; developer is not Netflix.
- innerHTML DOM-XSS sinks present across 20 content scripts injected into streaming platform pages.
- Privacy policy hosted on netflixparty.com (prior domain), not current teleparty.com; no retention disclosure.
- No developer name listed; 12 external JS hosts including posthog analytics and legacy netflixparty.com endpoint.
Evidence
- privacy_policy_broad_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0 (v3.5 rule D).
- brand_impersonation store brand_mention.is_impersonation=true, brands=['netflix'], confirmed_owner=false, verified_publisher=true → +1.0 Reputation.
- dom_xss_sinks crx 20 files contain dom_sink_innerhtml_userctrl; CSP present (csp_present=true) so +0.5 per finding, total +0.5 Code Quality (single bucket).
- verified_publisher store verified_publisher=true; -3.0 Reputation base. No monetization/CVE/stale triggers so full discount applies.
- external_hosts_count crx 12 distinct external JS hosts including us.i.posthog.com (analytics) and legacy wptony1.netflixparty.com; >3 domains → +1.5 Network.
- installs_high store 10,000,000 installs → +1.0+1.0+0.5 Webstore; partially offset by no bad-host/affiliate/monetization hits.
- no_developer_name store developer_name is empty string → +1.0 Reputation (no 'Offered by' name).
- privacy_policy_domain_mismatch store Privacy policy URL is netflixparty.com/privacy, not teleparty.com; no retention clause; -2.0 verified-publisher discount not applicable to privacy scope failure.
Permissions Breakdown
- activeTab low Grants access only to the current tab on user action; scoped and low-risk.
- storage low Local data persistence; no cross-origin data exposure.
- scripting medium Allows dynamic script injection into pages; medium risk but limited by activeTab scope.
- alarms low Timer/scheduling API; no data access.
Pillar Scores
Permissions1.60
Reputation5.00
Network2.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| <fsssiedxa$'sssiedx | 3.27 | Low | review | 2026-08-15 |
| dfb{{98991*97996}}xca | 3.08 | Low | review | 2026-08-05 |
| v3.6&n998352=v915771 | 2.05 | Low | review | 2026-08-05 |
| fsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx | 3.01 | Low | review | 2026-07-30 |
| fsssiedxd'sssiedx | 3.26 | Low | review | 2026-07-30 |
| sssieddrubricxsx | 3.11 | Low | review | 2026-07-30 |
| v3.6 | 3.74 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA
f1f971053b41…
Force block
— not fired
Score recovered
no
Elapsed
30.5s