UniBo Lessons to Google Calendar
cjkpabimmgbbommbopohkcokdmnghioj
Risk Score
3.79
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Free-webmail dev (gmail) with no verified business identity and no developer name listed.
- Privacy policy fetched but does not scope to this extension or disclose data collection details.
- External JS hosts include unknown domain www.harrytheo.com and goo.gl shortener — supply-chain surface.
- Brand impersonation flag: 'Google' mentioned but developer is not a confirmed Google entity.
- MV3 with no explicit CSP; 6 external JS hosts broaden network attack surface.
Evidence
- free_webmail_dev_no_name store Developer email is edoardo.nini@gmail.com; no developer name listed; no business website.
- privacy_policy_inadequate api Policy fetched (1139 chars); scope_extension=false, data_collection=false — generic GitHub page.
- external_js_hosts crx 6 external JS hosts: getbootstrap.com, github.com, goo.gl, popper.js.org, googleapis.com, harrytheo.com.
- brand_impersonation_flag api brand_mention.is_impersonation=true for 'google'; developer domain is gmail.com, confirmed_owner=false.
- no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit restriction on external scripts.
- tiny_install_base store Only 12 installs; no ratings. Very low blast radius but no community vetting signal.
- no_bad_hosts_no_cves api threat_intel bad_host_hits=[], monetization_hits=[], affiliate_hits=[]; cve_findings_raw=[].
- maintenance_moderate store Last updated Sep 2025; months_since_update=11 (3-12mo range → +3.5 maintenance score).
Permissions Breakdown
- identity low OAuth identity access; needed to push events to Google Calendar. No broad scopes declared.
- *://corsi.unibo.it/* low Narrow host: only the university course portal. Matches stated function.
- https://www.googleapis.com/* low Google Calendar API endpoint; matches stated function of adding calendar events.
Pillar Scores
Permissions1.00
Reputation7.00
Network2.00
Webstore2.50
Maintenance3.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:32
Listing SHA
a6215e14d3c8…
Force block
— not fired
Score recovered
no
Elapsed
—