Word Counter
cogpdhendieemlhgonhfoeajlakjiiai
Risk Score
4.24
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, yet admits data collection and third-party sharing.
- Developer uses free Gmail address with no verifiable business identity.
- Extension is 13 months stale with only 13 installs — low accountability.
- No content security policy (MV3 default applies but no explicit CSP declared).
- Free-webmail developer with no business domain raises identity verification concerns.
Evidence
- privacy_policy_generic api Policy URL is Google account privacy page: scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 Privacy (v3.5 rule D).
- developer_identity store Developer email emilyl2017.528@gmail.com is free webmail; no business website or verified publisher badge.
- maintenance_stale store Last updated May 15 2025; months_since_update=13 → +6.0 Maintenance pillar.
- permissions_narrow manifest Only scripting + activeTab declared; no host_permissions, no cookies, no broad URL patterns.
- code_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — no malicious indicators.
- threat_intel_clean api bad_host_hits, affiliate_hits, monetization_hits all empty; no bad network signals.
- cve_clean crx cve_findings_raw empty; no vulnerable libraries detected.
- reputation_free_webmail store Free-webmail dev + no business domain + not verified publisher → Reputation pillar 6.5.
Permissions Breakdown
- scripting medium Can inject JS into active tab; scoped to activeTab so reach is limited.
- activeTab low Access only to the currently active tab on user gesture; narrow scope.
Pillar Scores
Permissions1.30
Reputation6.50
Network2.00
Webstore0.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA
74813f1a8131…
Force block
— not fired
Score recovered
no
Elapsed
18.4s