Floating Video with Playback Controls
pnanegnllonoiklmmlegcaajoicfifcm
Risk Score
4.66
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing (Privacy pillar = 10).
- scripting + <all_urls> host permission allows arbitrary JS injection on every site user visits.
- new Function() constructor found in 4 JS files including background.js; dynamic code execution risk.
- Developer is anonymous (no dev name, free Gmail, no business domain); verified/featured status is anomalous.
- 13 months since last update; moderate staleness for an extension with broad host access.
Evidence
- generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — Privacy pillar = 10.
- broad_host_access manifest host_permissions=[<all_urls>] + content_scripts_matches=[<all_urls>] + scripting perm = high-capability combo.
- function_constructor_multi_file crx new Function() found in background.js, content.js, settings.js, window-content.js — dynamic execution in 4 of 5 JS files.
- anonymous_developer store developer_name empty; email terrazasterceroa88@gmail.com is free webmail; no business domain.
- verified_publisher_anomaly store Verified publisher + featured badges present but dev identity is anonymous Gmail; v3.5 invariant 0c does not fully mitigate.
- maintenance_staleness store 13 months since update (12-24mo band) → Maintenance pillar = 6.0.
- no_csp manifest csp_present=false on MV3; no additional network penalty (MV3 strict default) but compounds function_constructor risk.
- no_external_hosts crx js_external_hosts=[] and bad_host_hits=[]; no observed network exfiltration, limiting network pillar to 0.
Permissions Breakdown
- storage low Stores extension settings locally; low impact.
- activeTab medium Access to current tab on user action; moderate risk.
- scripting high Can inject scripts into pages; elevated risk when paired with <all_urls>.
- tabs medium Can read tab URLs and metadata across all tabs.
- <all_urls> (host) high Broad host access enables content injection on every site visited.
Pillar Scores
Permissions5.50
Reputation4.00
Network0.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:59
Listing SHA
e7cdff30814d…
Force block
— not fired
Score recovered
no
Elapsed
—