Clipboard Archive
pbdiacpehmcjhklkikdgmhpdjlgnlbad
Risk Score
6.62
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Abandoned extension (43 months stale) with <all_urls> content script — high takeover/compromise risk.
- Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail developer (gmail.com) with no verified business identity or privacy domain.
- scripting + <all_urls> allows arbitrary JS injection into every page visited.
- install_url_hijack=true and small-install/high-perm anomaly flag raises tail-attack-surface concern.
Evidence
- host_permissions_all_urls manifest <all_urls> host permission + content_scripts on <all_urls> gives full cross-origin page access.
- staleness store Last updated November 2022; 43 months since update — zombie extension with broad permissions.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_identity store Developer email is free webmail (gmail.com); no verified business domain or publisher badge.
- install_url_hijack crx install_url_hijack=true; extension opens a URL on install (target null — could not be confirmed benign).
- tail_attack_surface api install_perm_anomaly: small_install_high_perm=true, tail_attack_surface=true; 970 installs with HIGH perms.
- dom_xss_sink crx innerHTML assigned from variable in 471.js; no CSP present to mitigate XSS risk.
- no_csp manifest content_security_policy is null; no CSP hardens against script injection or XSS exploitation.
Permissions Breakdown
- contextMenus low Adds right-click menu entries; minimal risk on its own.
- storage low Local data persistence for clipboard history; expected for this category.
- tabs medium Can read tab URLs and titles; moderate privacy surface.
- scripting high Injects JS into pages; combined with <all_urls> gives full page access.
- <all_urls> (host_permissions) high Content script runs on every site; broad data exposure surface.
Pillar Scores
Permissions7.00
Reputation6.50
Network2.00
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA
9776d09b41bc…
Force block
— not fired
Score recovered
no
Elapsed
24.5s