Seven JSON Viewer
cfahdpkjihoomfomffdbmamapgdpohoe
Risk Score
5.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension last updated 47 months ago — effectively abandoned, no security fixes for nearly 4 years.
- Privacy policy is Google's generic account policy; scope_extension=false with data_collection+third_party_sharing=true triggers +10.0 privacy score.
- Developer uses free webmail (gmail) with no listed name or business website, raising accountability gap.
- Content scripts injected into all HTTP/HTTPS pages despite minimal declared permissions — broad reach.
- Verified-publisher discount capped at -1.0 due to stale update (>18mo) per invariant 0c.
Evidence
- maintenance_stale store Last updated July 2022; 47 months since update → maintenance pillar = 10.0.
- privacy_policy_generic store Policy is Google account policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
- verified_publisher_capped store verified_publisher=true and is_featured=true but months_since_update=47>18 caps discount at -1.0 per invariant 0c.
- free_webmail_no_name store developer_email=reezpatel@gmail.com, developer_name empty; free-webmail dev with no business entity raises reputation floor.
- content_scripts_broad manifest content_scripts_matches=[http://*/*, https://*/*] — injects into all pages despite only storage permission.
- no_cve_no_code_findings crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0 — no malicious code indicators.
- external_hosts crx js_external_hosts=[github.com, json.reez.dev]; 2 distinct domains, no bad-host hits, country_count=1.
- threat_intel_clean api bad_host_hits=[], affiliate_hits=[], monetization_hits=[], sibling_count=0, no ownership change.
Permissions Breakdown
- storage low Stores local settings/preferences; no cross-origin data access.
- content_scripts http://*/* https://*/* high Injects into all web pages; broad reach even without explicit host_permissions.
Pillar Scores
Permissions2.30
Reputation6.50
Network2.00
Webstore0.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA
31cd17e842e8…
Force block
— not fired
Score recovered
no
Elapsed
21.2s