Amazon Ads Blocker
pnpchphmplpdimbllknjoiopmfphellj
Risk Score
5.36
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection + third-party sharing but is not scoped to this extension (D rule: +10.0 privacy).
- Brand impersonation: 'Amazon' in title, developer domain gmail.com, confirmed_owner=false (+2.0 reputation).
- Uninstall and install URL hijack both flagged (+3.0+2.0 webstore).
- Description promises ad-blocking but lacks declarativeNetRequest/webRequest — capability mismatch (+2.0 webstore).
- Developer email is free-webmail with no verified business; no verified publisher or featured badge (+1.5 reputation).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; developer is gmail user, not Amazon; title exploits Amazon brand.
- privacy_policy_generic_with_data_sharing api PP fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D-rule +10.0 privacy.
- uninstall_url_hijack crx uninstall_url_hijack=true. Extension registers uninstall URL callback to 3rd-party target.
- install_url_hijack crx install_url_hijack=true. onInstalled opens 3rd-party URL — monetization/tracking pattern.
- description_permission_mismatch store Promises ad-blocking but has no declarativeNetRequest or webRequest permission declared.
- free_webmail_developer store Developer email 10xprofitio@gmail.com; no verified publisher; no featured badge.
- geo_diversity crx JS hosts span 4 countries (CN, FR, IE, US); category Adblock partially mitigates but still notable.
- host_permissions_amazon_all_tlds manifest Content scripts injected into all 23 Amazon TLDs; fits stated purpose but enables full page DOM access.
Permissions Breakdown
- storage low Stores extension settings locally; low inherent risk.
- host_permissions: *://*.amazon.*/ medium Broad read/write access across all Amazon TLDs; fits adblock claim but enables content scraping.
Pillar Scores
Permissions2.50
Reputation8.00
Network2.00
Webstore8.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:23
Listing SHA
cada7c8fe319…
Force block
— not fired
Score recovered
no
Elapsed
—