Launchpad Hero
bmkccjgdfgjhfjbghpapedknkdokebfi
Risk Score
3.36
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Developer uses free webmail (outlook.com) with no verified publisher badge — low accountability.
- Extension is 20 months stale (High maintenance risk) with 50K installs still active.
- DOM-XSS sink (innerHTML on user-controlled variable in popup.js) with no CSP to mitigate.
- Privacy policy discloses data collection and third-party sharing but extension has no declared permissions — scope mismatch warrants scrutiny.
- Manifest uses localized placeholders (__MSG_appName__) making store-listing verification harder.
Evidence
- developer_email_free_webmail store Developer email launchpadhero@outlook.com is a free webmail address; no verified publisher badge.
- months_since_update_20 store Last updated January 13, 2025; 20 months stale — scores in High maintenance band (6-12mo +3.5, 12-24mo +6.0 applied at 20mo).
- dom_sink_innerhtml_userctrl crx popup.js assigns user-controlled variable to innerHTML with no CSP; DOM-XSS risk.
- no_permissions_declared manifest permissions[], host_permissions[], and content_scripts_matches[] all empty — zero declared permissions.
- js_external_hosts_yahoo crx 12 Yahoo subdomains in js_external_hosts; extension contacts external hosts despite empty permissions — unusual.
- privacy_policy_data_collection_third_party api Privacy policy discloses data collection and third-party sharing; retention documented.
- csp_absent manifest content_security_policy is null; no CSP mitigates the innerHTML XSS sink.
- manifest_localized_placeholders manifest manifest_name and manifest_description use __MSG__ placeholders, obscuring store listing review.
Pillar Scores
Permissions0.00
Reputation6.50
Network2.00
Webstore1.00
Maintenance6.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 15:40
Listing SHA
f4791588db51…
Force block
— not fired
Score recovered
no
Elapsed
—