Anonymous Stories
djagffgjghpihfffmiomblhinennkkig
Risk Score
3.29
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — no extension-specific disclosure.
- Developer name field is empty; identity accountability is reduced.
- Extension not updated in 18 months; at the maintenance threshold boundary.
- No CSP declared (MV3 mitigates somewhat, but adds minor code-quality surface if findings emerge later).
- Host permission on instagram.com allows content script injection on all Instagram pages.
Evidence
- privacy_policy_generic store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — not scoped to this extension.
- verified_publisher store Developer domain invertexto.com resolves and verified_publisher=true; reputation partially mitigated.
- developer_name_missing store developer_name is empty string; no displayed 'Offered by' name reduces accountability.
- maintenance_stale store months_since_update=18; sits at 6-12mo boundary scoring +3.5 (exactly 18mo).
- no_csp manifest content_security_policy is null; MV3 provides default-src restrictions but no explicit policy declared.
- host_permission_instagram manifest Content scripts injected into https://*.instagram.com/* — matches stated anonymous stories function.
- no_bad_hosts_no_cves crx bad_host_hits=[], cve_findings_raw=[], affiliate_hits=[], obfuscation_score=0.0 — no active threat signals.
- installs_webstore store 10,000 installs, rating 4.9, no review red flags, sibling_count=0.
Permissions Breakdown
- storage low Stores local extension data; no cross-site exposure.
- tabs medium Can read tab URLs/titles; moderate privacy surface.
- https://*.instagram.com/* (host) medium Scoped to Instagram only; matches stated function but enables content injection on that domain.
Pillar Scores
Permissions1.60
Reputation4.00
Network0.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA
6e2a56b16a55…
Force block
— not fired
Score recovered
no
Elapsed
19.2s