SteamDBSecurity Analysis

Chromev4.33MV3March 16, 2026 at 07:52 PM
Use with caution

This extension requests significant permissions. It has 500K+ users, a 4.7 star rating, but review the findings below.

3.8MEDIUM
3.8 MEDIUMRaw: 4.7

This extension shows some risk signals that are common in legitimate extensions but worth reviewing. Check the details below.

Based on 43 permissions including high-risk ones, 28 code findings.

Trust Signals(5.5/10)

Users
500K
Rating
4.7(1K reviews)
Status
Featured
Permissions
7.5/10
Code
5.8/10
Combinations
0.0/10
Manifest/CSP
3.1/10

Permissions(43 analyzed)

Code Findings(7 patterns, 28 total)

Libraries(1 detected)

1 library detected

Content Security Policy

No CSP Defined(1 issue)
MEDIUM
N/ANo CSP defined

This extension does not define a Content Security Policy. A CSP helps prevent XSS and code injection attacks.

Manifest Analysis(1 finding)

Resolved from __MSG_* i18n placeholders:

Description: Adds SteamDB links and new features on the Steam store and community. View lowest game prices and stats.

MEDIUM
web_accessible_resourcesJS files exposed to web pages

JavaScript files are exposed as web-accessible resources. Matched websites can load and interact with extension scripts.

External Domains(18)

*.steampowered.comaddons.mozilla.orgapi.steamchina.comapi.steampowered.comchromewebstore.google.comcrowdin.comextension.steamdb.infogithub.comlucide.devmicrosoftedge.microsoft.compartner.steamgames.compcgamingwiki.comsteamcommunity.comsteamcommunity.com${profileurlsteamdb.infosteamhunters.comsteamstat.usstore.steampowered.com

Indicators of Compromise

7 indicators of compromise found

File Statistics

126
Total Files
49
JS Files
1.2 MB
Total Size

Other Scanned Extensions