Find
akaeoepndhnhffnginkbdcoigbpnnljh
Risk Score
3.09
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Content script on <all_urls> gives read/modify access to every page visited.
- Privacy policy is Google's generic account policy — not scoped to this extension at all.
- Free-webmail developer (gmail.com) with no verified business identity.
- No CSP declared (MV3 default applies, but adds no extension-specific hardening).
- Tiny install base (171) limits blast radius but also limits community vetting.
Evidence
- content_scripts_broad manifest content_scripts_matches includes <all_urls>, http://*/* and https://*/* — runs on every site.
- privacy_policy_generic store Policy URL is Google's account privacy page; scope_extension=false, does not describe this extension.
- privacy_policy_admits_data_and_3p_sharing api Classification: data_collection=true, third_party_sharing=true, scope_extension=false → +10.0 privacy pillar (v3.5 rule D).
- free_webmail_developer store Developer email soc221b.e@gmail.com with no registered business domain; domain_age_ct not queried.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit extension CSP set.
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, no external JS hosts beyond react.dev reference.
- no_bad_hosts_or_monetization api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[], sibling_count=0.
- recently_updated store Last updated March 7, 2026; months_since_update=3 → maintenance score 0.0.
Permissions Breakdown
- content_scripts <all_urls> high Content script injected on every URL; can read/modify all page content.
Pillar Scores
Permissions2.00
Reputation6.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
717a2efde804…
Force block
— not fired
Score recovered
no
Elapsed
20.6s