ChatGPT for StackOverflow
apjhekoaogdimcgiihoncakocdddhmlk
Risk Score
6.15
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Brand impersonation: extension name references both ChatGPT and StackOverflow without verified ownership of either brand.
- Privacy policy is Google's own generic policy — not scoped to this extension, admits data collection and third-party sharing.
- Extension is 39 months stale (zombie) with no CSP, raising supply-chain hijack risk.
- Developer uses free Gmail address with no verified business domain or publisher badge.
- Mixpanel analytics (api-js.mixpanel.com, cdn.mxpnl.com) bundled and contacting external hosts with no disclosed data handling.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands=['stackoverflow','chatgpt']; confirmed_owner=false; dev domain=gmail.com
- generic_privacy_policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true
- staleness store last_updated=March 1 2023; months_since_update=39; >36mo zombie threshold triggered
- no_csp manifest content_security_policy=null on MV3 extension; csp_present=false
- mixpanel_analytics crx js_external_hosts includes api-js.mixpanel.com and cdn.mxpnl.com; telemetry with no disclosed retention
- free_webmail_dev store developer_email=shobrookj@gmail.com; no business website; not verified publisher
- ai_page_content_processing manifest AI extension injecting into SO question pages and forwarding content to chat.openai.com
- is_featured_by_google store is_featured_by_google=true; partial trust signal, does not override impersonation/staleness risks
Permissions Breakdown
- storage low Stores local extension data; no user-data exfil risk on its own.
- https://*.openai.com/ (host_permission) medium Allows requests to OpenAI API; scoped to single domain, matches stated function.
- content_scripts on stackoverflow.com medium Injects JS into SO question pages; scoped narrowly to questions path.
Pillar Scores
Permissions2.30
Reputation7.50
Network4.00
Webstore4.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA
29c6a027b247…
Force block
— not fired
Score recovered
no
Elapsed
20.9s