Auto Highlight
dnkdpcbijfnmekbkchfjapfneigjomhh
Risk Score
4.01
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, yet admits data collection and third-party sharing.
- Extension has not been updated in 27 months (zombie-tier staleness).
- No developer display name; only email at personal domain reduces accountability.
- No CSP declared (MV3 default mitigates but no explicit policy).
- Moderate 3.7 rating with 20k installs warrants review.
Evidence
- privacy_policy_generic store Policy URL is myaccount.google.com — not extension-scoped; admits data_collection=true, third_party_sharing=true.
- maintenance_stale store Last updated March 2024; 27 months since update triggers +8.5 maintenance score.
- verified_publisher store Verified publisher badge present; -3.0 reputation discount applied but capped at -1.0 due to stale >18mo (0c).
- no_developer_name store developer_name is empty string; only email ds@dannyadam.com available.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; code quality pillar = 0.
- operator_cluster_clean api sibling_count=0; no sibling extensions under same fingerprint.
- installs_medium store 20,000 installs; +1.0 webstore signal applied.
Permissions Breakdown
- activeTab low Only accesses tab on user action; limited scope.
- contextMenus low Adds right-click menu items; no data exfil surface.
- scripting medium Can inject scripts into active tab; moderate capability.
- storage low Local preference storage; no exfil risk alone.
Pillar Scores
Permissions1.30
Reputation3.00
Network0.00
Webstore1.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA
66f79da94d4a…
Force block
— not fired
Score recovered
no
Elapsed
17.6s