Docs
aohghmighlieiainnegkcijnfilokake
Risk Score
4.83
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension last updated October 2017 (107 months ago) — severely abandoned, unpatched against any browser changes or vulnerabilities.
- Privacy policy is Google's generic account policy, not scoped to this extension; data_collection and third_party_sharing both true with no extension-specific scope.
- MV2 with no CSP: +2.0 Network penalty applies per v2 calibration rule (b).
- Triple-stale fingerprint: >24mo stale + MV2 + no CSP triggers webstore anomaly signal.
- No developer name listed in store; policy is generic, reducing transparency accountability.
Evidence
- verified_publisher store Google verified publisher; developer email docs-extension-support@google.com on google.com domain which resolves and is 20+ years old.
- maintenance_stale store Last updated October 2017, 107 months ago — worst maintenance band (>36mo), zombie booster does not apply (install_count unknown).
- privacy_policy_generic api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true: generic Google policy, not scoped to this extension.
- mv2_no_csp manifest Manifest V2 with null CSP. v2 calibration +2.0 Network penalty applied.
- triple_stale_fingerprint manifest >24mo stale + MV2 + no CVEs (CVE empty so no amplifier); v2 fix (c) +2.0 Webstore applied.
- zero_permissions manifest No declared permissions, host_permissions, or content_scripts. Minimal capability surface.
- js_external_host crx Single external JS host: docs.google.com — Google-owned, low risk.
- code_clean crx code_findings_raw empty, obfuscation_score 0.0, 1 JS file scanned. No malicious signals detected.
Pillar Scores
Permissions0.00
Reputation2.00
Network2.00
Webstore1.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-10 18:42
Listing SHA
7e559caee06f…
Force block
— not fired
Score recovered
no
Elapsed
—