uBlacklist
pncfbmialoiaghdehhbnbhkkgmjanfhe
Risk Score
2.69
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy lacks extension-specific scope and retention disclosure despite admitting data collection.
- declarativeNetRequestWithHostAccess enables network request blocking/redirecting across Google search domains.
- Free-webmail developer (gmail) with no verified publisher badge reduces accountability.
- scripting permission + content scripts across 180+ Google TLDs gives broad JS injection surface.
- identity permission enables OAuth token acquisition; could be misused if extension is compromised.
Evidence
- featured_by_google store Extension carries Google Featured badge, reducing reputation risk.
- privacy_policy_scope_mismatch api Policy fetched but scope_extension=false and data_collection=true; no retention info disclosed.
- free_webmail_developer store dev.iorate@gmail.com; no verified publisher badge; domain_age_ct not queried.
- no_csp manifest csp_present=false on MV3; MV3 has strict default so no penalty applied.
- no_bad_hosts_no_monetization api threat_intel shows empty bad_host_hits, monetization_hits, affiliate_hits.
- clean_code_scan crx code_findings_raw empty; obfuscation_score=0.0; no CVEs detected.
- content_scripts_reach manifest Content scripts injected into ~180 google.* TLD search URLs; scoped to /search? paths only.
- no_ownership_change api wayback_ownership.ownership_changed=false; operator_cluster sibling_count=0.
Permissions Breakdown
- activeTab low Scoped to user-initiated action; minimal passive access.
- alarms low Scheduling only; no data access.
- declarativeNetRequestWithHostAccess high Can block/redirect network requests; broad capability but matches stated filter function.
- identity medium OAuth token access; used for cloud sync (Google Drive/etc.).
- scripting medium Can inject JS into pages; scoped to Google search domains via content_scripts.
- storage low Local storage for blocklist rules; no exfil risk alone.
- unlimitedStorage low Allows large blocklist storage; no data access risk.
- content_scripts (google.*) medium Runs on all Google search TLDs; broad reach but scoped to search pages only.
Pillar Scores
Permissions3.50
Reputation4.50
Network0.00
Webstore1.00
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-07-17 05:26
Listing SHA
ef5a5e8a0760…
Force block
— not fired
Score recovered
no
Elapsed
—