Enhanced GitHub
anlikcnbgdeidpacdbdljnabclhahhmd
Risk Score
4.92
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; data collection and 3rd-party sharing admitted without context.
- Brand impersonation: 'github' mentioned in name by unverified gmail developer who is not confirmed GitHub owner.
- Developer uses free-webmail (gmail) with no business domain; accountability is limited.
- webRequest on all GitHub traffic gives broad traffic-observation capability with 24-month stale codebase.
- Extension stale at 24 months; borderline zombie risk as MV3 + no CVEs partially mitigates.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
- brand_impersonation store brand_mention.is_impersonation=true for 'github'; confirmed_owner=false; developer is gmail user.
- free_webmail_developer store Developer email varun2902@gmail.com; no business domain; Reputation base elevated.
- webRequest_permission manifest webRequest declared; scoped to *.github.com/* only; DeveloperTools category partially justifies.
- maintenance_stale store Last updated June 2024; months_since_update=24; Maintenance +6.0.
- description_mismatch store Promises download but lacks 'downloads' permission; mismatches non-empty → Webstore +2.0.
- featured_by_google store is_featured_by_google=true; applies -2.0 Reputation discount (featured badge).
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, cve_findings_raw empty; Code Quality=0.0.
Permissions Breakdown
- storage low Stores user preferences locally; minimal risk.
- webRequest high Can observe all network requests on github.com; elevated capability.
- webNavigation medium Monitors navigation events; needed for SPA routing on GitHub.
- *://*.github.com/* medium Scoped host access to GitHub only; justified for stated function.
Pillar Scores
Permissions3.50
Reputation6.50
Network2.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA
ae0998abc96f…
Force block
— not fired
Score recovered
no
Elapsed
20.5s