Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Purrfect Pomodoro Timer: Productivity, Time Management & Daily Journal

aobapnhgpjlldncjopmbbfeoomombhel
Risk Score
4.06
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 1,000
Rating 4.9
Last updated 2026-04-19 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer kartik.pomodoro@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • declarativeNetRequestWithHostAccess + <all_urls> lets extension intercept/modify requests on every site — unjustified for a Pomodoro timer.
  • Gmail developer account (kartik.pomodoro@gmail.com) with no verified business identity; no domain to anchor accountability.
  • Privacy policy admits data collection and third-party sharing (PostHog analytics, BuyMeACoffee) but omits retention period.
  • External JS loaded from raw.githubusercontent.com and www.jsdelivr.com — unversioned/CDN content could change without notice.
  • No CSP declared; MV3 default is stricter but external host list (9 domains) widens the network attack surface.

Evidence

  • high_capability_mismatch manifest declarativeNetRequestWithHostAccess + <all_urls> declared by a Pomodoro timer; no stated blocking/redirect function.
  • free_webmail_dev store Developer email kartik.pomodoro@gmail.com; no verified business domain or publisher badge.
  • privacy_policy_gaps api Policy fetched (1997 chars), scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • external_hosts_9 crx 9 external JS hosts: app.posthog.com, raw.githubusercontent.com, www.jsdelivr.com, buymeacoffee CDN, fonts.googleapis.com, forms.gle, kartikth40.github.io.
  • no_csp manifest content_security_policy is null; MV3 defaults apply but no explicit restriction on connect-src or script-src.
  • posthog_analytics crx app.posthog.com in external hosts confirms user-behaviour telemetry; policy mentions third-party sharing without retention detail.
  • no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty — code surface looks clean.
  • low_install_high_perm store Only 1,000 installs with HIGH-tier host permission; install_perm_anomaly.has_high_tier_permission=true.

Permissions Breakdown

  • storage low Stores timer/journal data locally; expected for productivity app.
  • notifications low Used to fire Pomodoro break alerts; fits stated function.
  • alarms low Schedules timer events; core productivity feature.
  • offscreen low Offscreen document for background audio/rendering; low standalone risk.
  • declarativeNetRequest medium Can block/redirect network requests; unexpected for a timer app.
  • declarativeNetRequestWithHostAccess high Elevates DNR to modify requests on all hosts; high capability mismatch for a timer.
  • <all_urls> (host_permissions) high Grants request interception across every site; unjustified for a Pomodoro timer.

Pillar Scores

Permissions6.50
Reputation6.50
Network4.50
Webstore2.50
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Scoring History

fsssiedxn0885a370za"n0885a370zsssiedx 3.63 Low review 2026-09-02
sssiedn253e6864dp727562726963xsx 3.42 Low review 2026-09-02
v3.6 4.06 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA f208ce0b1e65…
Force block — not fired
Score recovered no
Elapsed 24.7s