JSON Formatter
cigpimdanlhjegpobmgjpkpmcileefee
Risk Score
5.13
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension not updated in 44 months — stale and potentially abandoned.
- Privacy policy URL returns HTTP error; policy effectively inaccessible and unverifiable.
- No developer name listed; only email on a small-footprint domain.
- jquery 3.5.1 bundled with no CSP — minor DOM-sink exposure without policy enforcement.
- JS external hosts include getbootstrap.com, popper.js.org, github.com — external resource references though no remote loading detected.
Evidence
- maintenance_stale store Last updated October 2022; 44 months since update triggers maximum maintenance score (10.0).
- privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError); policy URL exists but unreachable — scored as no policy (+10.0).
- no_developer_name store developer_name is empty string; only email info@linangdata.com available.
- verified_publisher store verified_publisher=true; applies -3.0 reputation discount (floor 2.0).
- jquery_3_5_1_no_csp crx jquery@3.5.1 bundled; no CSP present. v2 rule: jquery<3.5 + no CSP +2.0 code quality — version is 3.5.1 so threshold not met; no CVEs found.
- cve_findings_empty crx cve_findings_raw=[]; no CVE exposure found for bundled libraries.
- js_external_hosts crx 4 external JS hosts: getbootstrap.com, github.com, linangdata.com, popper.js.org. No bad-host or monetization hits.
- obfuscation_none crx obfuscation_score=0.0; code_findings_raw=[]; no malicious indicators detected.
Permissions Breakdown
- clipboardRead medium Can read clipboard contents; relevant for JSON paste workflow but sensitive.
- clipboardWrite medium Can write to clipboard; paired with Read for format-and-copy workflow.
- contextMenus low Adds right-click menu entries; minimal risk.
Pillar Scores
Permissions2.00
Reputation4.00
Network1.50
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA
ed414b62aaf7…
Force block
— not fired
Score recovered
no
Elapsed
19.3s