Save to Bookmark OS
cnmnalakipnobjijcnnnkbpeejjhhdkn
Risk Score
4.34
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection AND third-party sharing but is not scoped to this extension — D rule → +10.0 privacy.
- Content scripts injected on ALL URLs (http://*/* + https://*/*) with no CSP, giving broad page-read capability.
- Extension is 19 months stale (6-12mo band → +3.5 maintenance); v3.5 invariant 0c caps verified-publisher discount.
- No developer display name increases identity accountability gap.
- tail_attack_surface flagged: small install base with HIGH-tier host permission raises acquisition-risk concern.
Evidence
- privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D → +10.0 privacy.
- broad_host_permissions manifest <all_urls> host permission + content_scripts on http://*/* and https://*/* — injected into every page visited.
- no_csp crx content_security_policy is null; MV3 strict default applies, mitigating eval risk but no explicit declaration.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discount capped at -1.0 due to months_since_update=19 (>18).
- maintenance_stale store Last updated November 2024; 19 months since update maps to 6-12mo band (+3.5) at scoring time.
- no_developer_name store developer_name is empty string; identity accountability reduced, +1.0 reputation.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; low-install + HIGH-perm flag → +1.0 webstore.
- clean_code_no_threats crx code_findings_raw empty, obfuscation_score=0.0, no bad/affiliate/monetization host hits, single US host.
Permissions Breakdown
- tabs medium Access to tab URLs/titles; needed for bookmark capture but enables browsing history inference.
- <all_urls> (host_permission) high Content scripts injected into every site via http://*/* and https://*/* — broad reach.
Pillar Scores
Permissions4.50
Reputation2.50
Network2.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA
978ef695976b…
Force block
— not fired
Score recovered
no
Elapsed
21.9s