I built a free Chrome extension security scanner now Fortune 500 teams use it

2 pointsposted 11 hours ago
by jensec

Item id: 46426302

1 Comments

efortis

11 hours ago

Scanned mine:

https://crxplorer.com?extensionId=babjpljmacbefcmlomjedmgmke...

It's getting a 20% safety score on CSP, saying:

> The complete absence of a Content Security Policy (CSP) is a critical security vulnerability…

But absence means that it uses the default, which is fine in my case:

https://developer.chrome.com/docs/extensions/reference/manif...

---

And 65% on permissions, (it uses "download") and it says:

> …its necessity is unclear without an overview of the extension’s specific purpose.

but its purpose is stated