Memo App
egmofikcmpeplgpkikcekolmhoighdcg
Risk Score
4.41
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy, not scoped to this extension; data collection and 3rd-party sharing admitted without extension context.
- Developer uses free Gmail account with no verifiable business identity.
- Extension is 24 months stale (maintenance threshold: 6.0).
- No CSP present (MV3 default strict, but adds network uncertainty if code evolves).
- Tiny install base (9) means no community vetting; unknown quality of the single JS file.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
- developer_email_free_webmail manifest specialing1219@gmail.com — no verified business domain; Reputation starts at 5.0, +1.5 free-webmail.
- months_since_update_24 store Last updated June 2024; 24 months → Maintenance pillar 6.0.
- no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP declared.
- cve_findings_empty crx No CVEs found; CVE pillar = 0.0.
- code_findings_empty crx No malicious code signals detected; obfuscation_score=0.0.
- low_installs store Only 9 installs; no community trust signal, install_perm_anomaly flags false.
- threat_intel_clean api bad_host_hits, affiliate_hits, monetization_hits all empty; no threat-intel elevation.
Permissions Breakdown
- storage low Local data persistence; expected for a memo app.
- downloads medium Can trigger file downloads; slightly elevated but consistent with exporting memos.
Pillar Scores
Permissions0.60
Reputation6.50
Network2.00
Webstore0.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
6cce6027d7f4…
Force block
— not fired
Score recovered
no
Elapsed
18.1s