Fira Code for StackOverflow
ecldaajhgjoideepdlajkipnkblnkjhn
Risk Score
5.12
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Abandoned: 54 months since last update, no maintenance signal.
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- Brand impersonation flag: extension name references StackOverflow and GitHub without confirmed ownership.
- Developer email on gmx.de (free webmail), flagged looks_throwaway by threat intel.
- Featured badge mitigates somewhat, but staleness and generic policy remain unresolved.
Evidence
- maintenance_stale store Last updated December 4, 2021 — 54 months ago; no changelog visible.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- brand_impersonation store brand_mention.is_impersonation=true; mentions github and stackoverflow; confirmed_owner=false.
- developer_throwaway_domain api Developer email schmelzer.martin@gmx.de; threat_intel flags looks_throwaway=true.
- featured_by_google store is_featured_by_google=true; partial trust signal reduces reputation risk.
- no_cve_no_bad_hosts crx cve_findings_raw empty; bad_host_hits empty; js_external_hosts empty.
- low_install_count store Only 71 installs; blast radius minimal.
- code_clean crx code_findings_raw empty; obfuscation_score=0.0; no eval/fetch/redirect findings.
Permissions Breakdown
- storage low Stores extension settings locally; minimal risk.
- content_scripts *://*.stackoverflow.com/* low Scoped to stackoverflow.com only; matches stated font-injection function.
Pillar Scores
Permissions0.30
Reputation6.50
Network0.00
Webstore3.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA
b0edf6ac64f3…
Force block
— not fired
Score recovered
no
Elapsed
18.0s