GIF maker
ceffdaejjmgmgpokomlllneofpfbkgop
Risk Score
3.27
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing (D rule: +10.0).
- Developer uses free Gmail address with no verifiable business identity, raising reputation risk.
- No CSP declared (MV3 so no +2.0 network penalty, but inherently less hardened).
- Very low install count (34) limits blast radius but reduces vetting signal.
- Maintenance score elevated: 11 months since last update approaching 12-month threshold.
Evidence
- privacy_policy_generic store Policy URL is myaccount.google.com — Google's own account policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- free_webmail_developer store Developer email aleksanderdanilian@gmail.com is free Gmail; no business domain. Reputation starts 5.0 +1.5 → 6.5.
- no_permissions manifest permissions[] and host_permissions[] both empty; no chrome_url_overrides or chrome_settings_overrides. Permissions pillar = 0.0.
- no_csp manifest content_security_policy is null. MV3 default applies; no additional network penalty under v2 rule.
- maintenance_3_6mo store 11 months since update — in the 6–12 month band → +3.5 maintenance score.
- code_clean crx code_findings_raw=[], obfuscation_score=0.0, no external hosts beyond github.com. Code quality = 0.0.
- no_cve_findings crx cve_findings_raw empty; js_libraries detected (browser-pack, events) with unknown versions but no CVEs matched.
- threat_intel_clean api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], sibling_count=0. No threat-intel signals.
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore0.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA
83e71c5abcf6…
Force block
— not fired
Score recovered
no
Elapsed
19.2s