EcoIndex.fr
apeadjelacokohnkfclnhjlihklpclmp
Risk Score
2.42
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy, not scoped to this extension — admits data collection and 3rd-party sharing.
- No content_security_policy declared (MV3 default mitigates, but absence still noted).
- Unverified publisher with no Google badge; small install base limits trust signals.
- Rating is 0 with no reviews — no community validation available.
Evidence
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — scores +10.0 under v3.5 rule D.
- permissions_minimal manifest Only activeTab and storage declared; host_permissions scoped to bff.ecoindex.fr.
- no_cve_findings crx cve_findings_raw is empty; no known vulnerable libraries detected.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, 3 JS files scanned cleanly.
- threat_intel_clean api No bad_host_hits, monetization_hits, or affiliate_hits; developer domain resolves, looks_throwaway=false.
- recently_updated store months_since_update=0; maintenance risk is minimal.
- unverified_publisher store verified_publisher=false, is_featured_by_google=false; reputation starts at 5.0 with no adjustments.
- operator_cluster_clean api sibling_count=0; no cluster risk.
Permissions Breakdown
- activeTab low Grants access only to current tab on user action; limited blast radius.
- storage low Local extension data only; no cross-site or sensitive data access.
- https://bff.ecoindex.fr/* low Scoped host permission to developer's own API domain; narrow surface.
Pillar Scores
Permissions0.60
Reputation5.00
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:25
Listing SHA
704370bb68fb…
Force block
— not fired
Score recovered
no
Elapsed
—