Microsoft Single Sign On
ppnbnpeolgkicgegkbkbjmhlideopiji
Risk Score
2.54
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- nativeMessaging with recognized publisher but content_script on all HTTPS pages creates broad OS+web surface at 35M installs.
- Privacy policy fetch failed (HTTP error); policy adequacy cannot be confirmed — scored as unfetched (+10.0 privacy pillar).
- 22 months since last update approaches stale threshold; large install base amplifies exposure window.
- Rating of 2.2 is low for a 35M-install Microsoft extension — may indicate functional issues or user dissatisfaction.
- Content scripts on https://*/* paired with nativeMessaging: if compromised, attacker can read page content and relay to OS.
Evidence
- nativeMessaging + recognized publisher manifest nativeMessaging declared; native_messaging_check.publisher_recognized=true reduces risk but capability remains HIGH.
- content_scripts broad host manifest content_scripts_matches=['https://*/*'] — runs on every HTTPS page visited by user.
- privacy policy fetch failed crx privacy_policy_classification.fetched=false (fetch_error:HTTPError); cannot confirm scope or data handling.
- developer identity confirmed store brand_mention.confirmed_owner=true, developer_domain=microsoft.com, resolves=true, not throwaway.
- stale update store Last updated August 2, 2024; months_since_update=22 — approaching 24-month stale band.
- no CVEs, no bad hosts, no obfuscation crx cve_findings_raw=[], bad_host_hits=[], obfuscation_score=0.0, code_findings_raw=[] — clean code signals.
- strong CSP manifest CSP: script-src 'self', base-uri 'none', form-action 'none', default-src 'none' — well-locked down.
- low rating at massive install base store Rating 2.2 with 35M installs; no review red flags matched for malware/redirect, likely functional complaints.
Permissions Breakdown
- nativeMessaging high Allows communication with native OS apps; broad OS-level capability, recognized publisher mitigates but still high-risk.
- content_scripts https://*/* high Content script runs on all HTTPS pages — broad page-content access across every site user visits.
Pillar Scores
Permissions3.50
Reputation2.00
Network0.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 2.97 | Low | review | 2026-08-05 |
| v3.6&n971696=v905194 | 3.04 | Low | review | 2026-08-05 |
| v3.6 | 2.54 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:06
Listing SHA
118a59b362d8…
Force block
— not fired
Score recovered
no
Elapsed
20.7s