Email checker - verify email address in 1-click
eheagnmidghfknkcaehacggccfiidhik
Risk Score
4.79
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — unscoped, admits data collection & 3rd-party sharing; scores maximum 10.
- Install URL hijack: onInstalled opens https://email-checker.pro/welcome (+2.0 Webstore).
- Uninstall URL hijack declared (+3.0 Webstore).
- Extension is 22 months stale (>18mo), triggering maintenance penalty and capping verified-publisher discount.
- No developer name listed, reducing accountability despite verified-publisher badge.
Evidence
- install_url_hijack crx onInstalled opens https://email-checker.pro/welcome — unsolicited tab open on install.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() declared; target not resolved but flag is true.
- generic_privacy_policy store Policy URL is Google's own privacy page (myaccount.google.com), not scoped to this extension; data_collection=true, third_party_sharing=true.
- no_developer_name store developer_name is empty string; no 'Offered by' identity visible.
- verified_publisher_capped store verified_publisher=true but months_since_update=22 (>18mo) caps discount to -1.0 per invariant 0c/3.5E.
- stale_extension store 22 months since last update; maintenance score 6.0 (12-24mo band).
- external_js_host crx js_external_hosts: ['email-checker.pro'] — extension contacts developer domain at runtime.
- csp_absent_mv3 manifest content_security_policy is null; MV3 has strict defaults so no Network penalty applied, but no explicit CSP.
Permissions Breakdown
- contextMenus low Adds right-click menu items; low standalone risk.
- storage low Local key-value storage only; no exfil risk alone.
Pillar Scores
Permissions0.60
Reputation5.50
Network0.00
Webstore7.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:54
Listing SHA
75534af98fef…
Force block
— not fired
Score recovered
no
Elapsed
—