| declarativeNetRequest | Permission | | This permission allows the extension to define rules to block, redirect, or modify network requests. Rated Critical because it can control all network traffic, potentially blocking security updates or redirecting to malicious sites. |
| <all_urls> | Host | | Broad host access — the extension can read/modify content on every website. |
| identity | Permission | | This permission accesses Chrome identity service and user information. Rated High because it can obtain OAuth tokens, access connected accounts, and impersonate the user in authenticated service. |
| identity.email | Permission | | This permission directly accesses the user's email address. Rated High because it reveals personally identifiable information and can be used for tracking or targeting. |
| Contextual Risk Factors | Risk Factor | | The following context increases the overall risk:• 20% increase: Access to sensitive domains increases potential impact |
| Broad Host Permissions | Risk Factor | | This extension has broad host permissions allowing it to access many or all websites. |
| Broad Content Script Access | Risk Factor | | This extension can inject scripts into any website. |
| activeTab | Permission | | This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions. |
| storage | Permission | | This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads. |
| tabs | Permission | | This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns. |
| *://tinder.com/* | Host | | Host permission — access limited to this URL pattern. |
| https://with.is/* | Host | | Host permission — access limited to this URL pattern. |
| *://*.with.is/* | Host | | Host permission — access limited to this URL pattern. |
| *://*.google-analytics.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://*.googletagmanager.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://*.newrelic.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://*.nr-data.net/* | Host | | Host permission — access limited to this URL pattern. |
| *://*.google.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://*.google.co.jp/* | Host | | Host permission — access limited to this URL pattern. |
| *://*.gotinder.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://*.bugsnag.com/* | Host | | Host permission — access limited to this URL pattern. |
| *://*.sentry.io/* | Host | | Host permission — access limited to this URL pattern. |
| Access to Sensitive Domains | Risk Factor | | This extension requests access to sensitive domains: *://*.google-analytics.com/*, *://*.googletagmanager.com/*, *://*.google.com/*, *://*.google.co.jp/* |