Video Player
phdogoeljjbggglcgpkiabgdkkncgohe
Risk Score
5.98
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Abandoned: 53 months without update on an extension injected into every page.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Content script runs on <all_urls> giving broad DOM read/write access on every site visited.
- Gmail developer with no business domain — low accountability.
- description_promise.is_shell_pattern=true: vague 'video player' shell with broad host injection.
Evidence
- content_scripts_matches=<all_urls> manifest Content script injected on all URLs despite no declared permissions[] — broad reach.
- months_since_update=53 store Last updated January 2022; >36 months stale — maintenance pillar maxed.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- dom_sink_innerhtml_userctrl crx innerHTML sink in content_script.js; no CSP present — elevated XSS risk.
- developer_email=gmail.com store Free-webmail dev email, no business website — reduced accountability.
- is_shell_pattern=true store description_promise flags shell pattern: generic video-player promise with <all_urls> injection.
- is_featured_by_google=true store Extension carries Featured badge — partial trust signal, partially offsets reputation.
- cve_findings_raw=empty crx No CVEs detected in bundled libraries.
Permissions Breakdown
- content_scripts:<all_urls> high Content script injected on every site — broad DOM access across all origins.
Pillar Scores
Permissions3.50
Reputation6.50
Network0.00
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA
feb01afebfa6…
Force block
— not fired
Score recovered
no
Elapsed
20.1s