Weather Widget
cbfonhkeidkoldmfnffmpejogimdjknc
Risk Score
3.38
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Content script declared on <all_urls> runs on every page despite no other permissions declared.
- Developer uses free Gmail address with no verified business identity.
- Privacy policy is only 160 chars, hosted on free GitHub Pages, lacks retention disclosure.
- No CSP declared (MV3 default applies, but adds no extra hardening signal).
- jquery 3.5.1 bundled — minor known CVEs exist in older patch levels; no code findings detected.
Evidence
- content_scripts_matches:<all_urls> manifest Content script injected on all URLs; broad site reach with no declared permission guards.
- gmail_developer store Developer email rohanbpatil77@gmail.com is free webmail; no business domain verified.
- privacy_policy_very_short crx Policy fetched but only 160 chars; scope_extension=true, data_collection=true, retention=false.
- third_party_silence api Privacy policy does not mention third-party data sharing (+1.0 to privacy pillar).
- jquery_3.5.1_bundled crx jquery 3.5.1 detected; no CVEs flagged in cve_findings_raw but version is not fully patched.
- single_external_host crx Only api.openweathermap.org contacted; consistent with stated weather widget function.
- is_featured_by_google store Extension carries Google Featured badge, partial trust signal.
- maintenance_6_12mo store Last updated August 2025; ~10 months ago — moderate staleness tier.
Permissions Breakdown
- content_scripts:<all_urls> high Content script injected on every site visited; broad reach despite no declared permissions.
Pillar Scores
Permissions3.50
Reputation6.50
Network2.00
Webstore1.50
Maintenance3.50
Privacy2.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA
1cde4f7c513b…
Force block
— not fired
Score recovered
no
Elapsed
17.9s