StackOverflow Answer
bmlkdgmiaemiaopodggkhfblhmefimoi
Risk Score
5.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic GitHub policy) — scores max privacy risk.
- Extension is 42 months stale (>36mo) — abandoned, no security updates, zombie risk.
- Brand impersonation: mentions 'stackoverflow' and 'google' without verified ownership; free-webmail developer.
- Broad content_scripts on all URLs (http://*/* https://*/*) despite only needing StackOverflow/Google — high reach with no CSP.
- No CSP present on MV3 extension contacting external hosts (api.stackexchange.com, cdn.jsdelivr.net).
Evidence
- privacy_policy_generic_admits_sharing store Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — generic non-scoped policy admitting data sharing.
- stale_42_months store Last updated December 2022; 42 months since update — maintenance pillar maxed.
- brand_impersonation store brand_mention.is_impersonation=true; brands: google, stackoverflow; developer_domain=gmail.com, not verified.
- free_webmail_developer store Developer email renouxpro@gmail.com — free webmail, no verified business domain.
- broad_content_scripts manifest content_scripts_matches: http://*/* and https://*/* — runs on all sites despite narrow stated purpose.
- no_csp_external_hosts crx csp_present=false; external hosts: api.stackexchange.com, cdn.jsdelivr.net, www.apache.org.
- is_featured_by_google store is_featured_by_google=true — partial trust signal, offsets reputation slightly.
- no_bad_hosts_no_cves crx bad_host_hits empty, cve_findings_raw empty, code_findings_raw empty, obfuscation_score=0.0.
Permissions Breakdown
- storage low Stores local extension data only; no cross-site risk.
- content_scripts http://*/* https://*/* high Broad content script injection on all sites elevates reach significantly.
Pillar Scores
Permissions2.30
Reputation7.50
Network2.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA
d10fbb9f9a66…
Force block
— not fired
Score recovered
no
Elapsed
20.0s