doqment PDF Reader
ajmcpdllaaklaocodbnllhkaflncmlog
Risk Score
3.08
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- Developer uses free webmail (gmail.com) with no verified business identity.
- install_url_hijack flag set (install_url_target is null — may open a page on install).
- CSP allows 'wasm-unsafe-eval' which is an elevated WebAssembly execution vector.
- Small install base (3,000) reduces trust signal; no verified publisher badge.
Evidence
- privacy_policy_generic store Policy URL is Google account privacy policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- developer_email_free_webmail store Developer email shivaprsdv@gmail.com is free webmail; no verified business domain; reputation raised.
- install_url_hijack crx install_url_hijack=true but target is null; possible onInstalled redirect; no confirmed 3rd-party target.
- featured_by_google store is_featured_by_google=true → -2.0 reputation discount applied.
- csp_wasm_unsafe_eval manifest CSP script-src includes 'wasm-unsafe-eval'; appropriate for PDF renderer (pdfjs) but worth noting.
- no_cve_findings crx cve_findings_raw=[] and js_libraries_detected=[]; no known vulnerable libraries bundled.
- no_code_findings crx code_findings_raw=[] and obfuscation_score=0.0; code quality clean.
- no_bad_host_hits api threat_intel bad_host_hits, affiliate_hits, monetization_hits all empty; js_external_hosts limited to drafts.csswg.org and github.com.
Permissions Breakdown
- activeTab low Grants access only to the current tab on user action; narrow scope.
- contextMenus low Adds right-click menu items; no data access.
- scripting medium Can inject scripts into pages; paired with activeTab limits to user-triggered use.
Pillar Scores
Permissions1.30
Reputation6.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
079fed043eb7…
Force block
— not fired
Score recovered
no
Elapsed
20.3s