StackOverflow Tweaks Tool
dfignoicphdepgloiodeaiokaepjbnan
Risk Score
4.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- Brand impersonation: 'stackoverflow' in name; developer is unverified gmail user with no business domain.
- Extension is 22 months stale (no update since Aug 2024); maintenance risk rising.
- Developer uses free webmail (gmail) with no verified business identity or publisher badge.
- No CSP present (MV3 mitigates somewhat but adds mild network risk surface).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; 'stackoverflow' in title; developer domain is gmail.com, not stackoverflow.com.
- privacy_policy_generic store Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- free_webmail_developer store Developer email fasanriccardo21@gmail.com; no verified publisher badge; no business domain.
- maintenance_stale store months_since_update=22; falls in 12-24mo band → +6.0 maintenance pillar.
- no_csp manifest content_security_policy=null; MV3 so no v2 +2.0 penalty, but inherently no declared CSP.
- narrow_host_scope manifest content_scripts limited to *://*.stackoverflow.com/questions/*/*; no broad host permissions declared.
- is_featured_by_google store is_featured_by_google=true; provides -2.0 reputation discount capped per featured badge.
- no_bad_hosts_or_cves crx cve_findings_raw=[], bad_host_hits=[], code_findings_raw=[]; no malicious signals detected.
Permissions Breakdown
- storage low Stores user preferences locally; no cross-origin data access.
- content_scripts *://*.stackoverflow.com/questions/*/* low Narrowly scoped to stackoverflow question pages only; low blast radius.
Pillar Scores
Permissions0.50
Reputation7.00
Network0.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA
49ef7fb7b5c8…
Force block
— not fired
Score recovered
no
Elapsed
19.0s