Anonymous Extension
dpobhogjdfjlgiejbbojhablmlighflg
Risk Score
2.71
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing; scores maximum Privacy pillar risk.
- Extension loads from cdn.jsdelivr.net (external JS host); no CSP present on MV3 extension.
- Small install base (1,000) with no rating count — limited community validation.
- Developer domain kgsensei.dev cert-age not verifiable (CT lookup timed out).
- Featured badge present but no verified publisher — discount is limited.
Evidence
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy.
- external_js_host crx js_external_hosts: cdn.jsdelivr.net present; no CSP; MV3 so no +2.0 MV2 penalty but host noted.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
- no_code_findings crx code_findings_raw is empty; obfuscation_score=0.0; code_quality = 0.0.
- featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied (Follows recommended practices).
- maintenance_3_6mo store months_since_update=4; in 3-6 month band → +1.5 maintenance.
- no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty; developer domain resolves and not throwaway.
- no_operator_siblings api operator_cluster.sibling_count=0; no cluster risk.
Permissions Breakdown
- declarativeNetRequest medium Can block/redirect network requests; matched to stated adblock/privacy function.
- storage low Local data persistence only; no exfil risk on its own.
Pillar Scores
Permissions1.30
Reputation4.50
Network0.00
Webstore0.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA
f30905e03b65…
Force block
— not fired
Score recovered
no
Elapsed
18.8s