Simply Tasks - ToDo List
cmpgbgkmnbfdhmmalcafamkloghpgigk
Risk Score
4.10
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- Extension last updated May 2023 (~25 months ago) — effectively abandoned.
- Developer uses free Gmail address with no verified business identity.
- No 'Offered by' developer name visible; accountability gap.
- Very low install count (129) limits blast radius but reduces vetting signal.
Evidence
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
- maintenance_stale store Last updated May 7, 2023 (~25 months ago); maintenance pillar 8.5.
- developer_free_webmail store Developer email mohammedsohaibuddin101@gmail.com is free webmail; no verified business domain.
- featured_by_google store Extension is_featured_by_google=true; provides partial reputation offset but does not fix stale/privacy issues.
- permissions_minimal manifest Only 'storage' declared; MV3, no host permissions, no content scripts — minimal capability surface.
- csp_present_strict manifest CSP: script-src 'self'; object-src 'self'; — strict, no remote sources.
- no_bad_hosts_or_cves crx threat_intel bad_host_hits, affiliate_hits, monetization_hits all empty; cve_findings_raw empty.
- code_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — no malicious code indicators.
Permissions Breakdown
- storage low Needed to persist task data locally; low risk for a to-do list extension.
Pillar Scores
Permissions0.30
Reputation6.50
Network0.00
Webstore0.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 05:58
Listing SHA
48efab60d720…
Force block
— not fired
Score recovered
no
Elapsed
17.7s