Share via Telegram
phhmllhhondgbkaifcompghkadamdanc
Risk Score
6.28
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Brand impersonation: developer_name='Telegram' with gmail.com email; not verified owner of brand.
- Privacy policy is Google's generic account policy — scope_extension=false, collects+shares data; counts as +10.0.
- Extension abandoned >36 months ago (42mo); zombie risk with 1k installs.
- Install URL hijack flagged (install_url_hijack=true); onInstalled may open 3rd-party URL.
- Free-webmail developer email (gmail) + impersonating recognized brand with no business website.
Evidence
- brand_impersonation store developer_name='Telegram', brand_mention.is_impersonation=true, confirmed_owner=false, email=gmail.com
- generic_privacy_policy api Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy
- install_url_hijack crx install_url_hijack=true; onInstalled opens 3rd-party URL (target null but flag set)
- abandoned_extension store Last updated Dec 2022; months_since_update=42; >36mo stale with 1k installs
- free_webmail_developer store Developer email shareviatelegram@gmail.com; no business domain; impersonating Telegram brand
- no_csp manifest content_security_policy=null; MV3 has strict default but no explicit CSP declared
- low_installs store Only 1,000 installs; tail-attack-surface low but brand impersonation amplifies risk
- external_host crx js_external_hosts=['t.me']; contacts Telegram short-link domain, consistent with stated function
Permissions Breakdown
- contextMenus low Adds right-click share menu; low capability, expected for this function.
- tabs medium Can read current tab URL/title; needed to share page but grants some browsing visibility.
Pillar Scores
Permissions1.30
Reputation8.50
Network0.00
Webstore6.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA
efdfd2dd0946…
Force block
— not fired
Score recovered
no
Elapsed
19.5s