DNS Configuration Manager
opoejijmagmdeeobilcpjnllpmoklnlk
Risk Score
2.43
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy URL unreachable (fetch_error) — cannot verify data handling claims.
- new Function() in bundled test files enables arbitrary code execution if input reaches them.
- innerHTML user-controlled sink in popup.js is a DOM-XSS vector.
- Extension 6–12 months stale (Maintenance +3.5); DNS tool with no host perms but unclear update cadence.
- Unverified solo developer; no verified-publisher badge reduces accountability.
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (ConnectionError); policy scored as inaccessible → +10.0 privacy.
- function_constructor_in_test_files crx new Function() found in comprehensive-test.js and test-extension.js; appears test scaffolding but bundled in crx.
- dom_xss_sink crx popup.js assigns user-controlled variable to innerHTML; CSP present but doesn't fully mitigate DOM-XSS.
- maintenance_stale store months_since_update=11; falls in 6–12mo band → +3.5.
- no_verified_publisher store verified_publisher=false, not featured; reputation starts 5.0 with no adjustments.
- low_install_count store Only 1,000 installs; blast radius limited but tail-attack-surface flag not triggered per install_perm_anomaly.
- js_external_host_dev_domain crx js_external_hosts=['mohammadnasser.com']; single dev-owned domain, no third-party CDN.
- cve_findings_empty crx No CVEs detected in bundled libraries; CVE pillar=0.0.
Permissions Breakdown
- storage low Stores DNS config settings locally; low risk.
- alarms low Periodic background tasks; no data exfil capability on its own.
Pillar Scores
Permissions0.60
Reputation5.00
Network0.00
Webstore0.00
Maintenance3.50
Privacy10.00
Code Quality3.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA
fb0b046a6a0e…
Force block
— not fired
Score recovered
no
Elapsed
23.7s