JSON Formatter
cphfacjkoohfjagncdgakmjeheomgjih
Risk Score
5.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Abandoned: last updated 37 months ago, well past >36mo stale threshold.
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing (D rule: +10.0).
- Content script declared on <all_urls> — runs on every site the user visits despite low install count.
- No CSP and MV3 default strict but content_scripts <all_urls> broadens passive reach.
- Low install count (67) limits blast radius but stale + unscoped policy elevates residual risk.
Evidence
- content_scripts_matches=<all_urls> manifest Content script injected on every URL; broader than activeTab alone.
- months_since_update=37 store Last updated May 2023; >36 months stale → maintenance pillar 10.0.
- privacy_policy_generic_google store Policy URL is myaccount.google.com — not extension-scoped; data_collection+third_party_sharing=true → privacy +10.0.
- is_featured_by_google=true store Featured badge provides minor reputation credit.
- cve_findings_raw=[] crx No CVEs detected in bundled libraries.
- code_findings_raw=[] crx No malicious code patterns detected; obfuscation_score=0.0.
- threat_intel_clean api No bad hosts, monetization hits, or affiliate hits detected.
- operator_cluster_sibling_count=0 api No sibling extensions under same developer fingerprint.
Permissions Breakdown
- scripting medium Can inject scripts into pages; paired with activeTab limits scope to user-invoked tabs.
- activeTab low Access limited to currently active tab on user action; narrow scope.
- content_scripts <all_urls> high Content script runs on every URL, expanding reach beyond activeTab's user-gesture gate.
Pillar Scores
Permissions3.50
Reputation4.50
Network2.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA
2e9ab970b132…
Force block
— not fired
Score recovered
no
Elapsed
19.2s