Knowt: Quizlet Import, AI Notes & Flashcards
akegecpdcdbkjioddaingaedacjgfjhm
Risk Score
4.71
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but does NOT scope to this extension, and explicitly admits data collection and third-party sharing — scores maximum privacy risk.
- scripting + <all_urls> allows arbitrary JS injection on every page the user visits; AI category means page content is processed.
- AI/Gen-AI extension processes page content across all URLs — high content-exfil surface even without detected code findings.
- No developer name listed in store; reduces accountability signal despite featured badge.
- External JS hosts include s3.amazonaws.com and fonts.cdnfonts.com — remote CDN-served resources could change independently of CRX review.
Evidence
- privacy_policy_scope_missing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → triggers +10.0 privacy (D rule).
- broad_host_with_scripting manifest scripting + <all_urls>: can inject JS on any page. AI category amplifies content-exfil risk.
- ai_extension_page_content store AI Notes & Flashcards processes arbitrary page content; +2.5 webstore AI signal applied.
- featured_by_google store Google Featured badge grants -2.0 reputation discount.
- no_developer_name store developer_name is empty string; +1.0 reputation penalty for missing Offered-by.
- external_js_hosts crx fonts.cdnfonts.com, github.com, mui.com, s3.amazonaws.com — 4 distinct external domains.
- no_cve_findings api cve_findings_raw is empty; CVE pillar = 0.0.
- code_findings_clean crx code_findings_raw empty, obfuscation_score=0.0; code quality pillar = 0.0.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata across all open tabs.
- sidePanel low Opens a side panel UI; low direct risk on its own.
- scripting high Can inject JS into any page when combined with <all_urls> host permission.
- storage low Local extension storage; no cross-origin data access.
- <all_urls> high Broad host access enables content script injection and data reads on every site.
Pillar Scores
Permissions5.50
Reputation4.00
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-18 07:58
Listing SHA
5bfc940c69d6…
Force block
— not fired
Score recovered
no
Elapsed
—