Create Shortcut
ehmkjaagddnjkgghllbchghdehmgplpf
Risk Score
3.77
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Developer uses free webmail (gmail.com); no verified business identity.
- Privacy policy not scoped to this extension; data_collection not confirmed absent.
- No CSP declared (MV3 mitigates somewhat, but adds minor network risk).
- Maintenance gap: 13 months since last update.
- Small install base (804) limits trust signal from community usage.
Evidence
- free_webmail_developer store Developer email is tackn.jp@gmail.com — free webmail, no verified business entity.
- privacy_policy_not_extension_scoped api Policy fetched but scope_extension=false, data_collection=false → +9.0 privacy per v3 FIX A.
- no_csp manifest content_security_policy is null; MV3 default CSP applies, +2.0 Network (MV2+no CSP rule does not apply to MV3).
- is_featured_by_google store Extension carries Google Featured badge, applying -2.0 reputation discount.
- maintenance_gap store 13 months since last update falls in 12-24mo band: +6.0 maintenance score.
- no_bad_hosts_no_affiliates api threat_intel shows no bad_host_hits, affiliate_hits, or monetization_hits.
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty.
- no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.
Permissions Breakdown
- contextMenus low Adds right-click menu items; low standalone risk.
- downloads medium Can initiate file downloads; used here to create shortcut files.
Pillar Scores
Permissions1.30
Reputation6.50
Network2.00
Webstore0.00
Maintenance6.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
11510f7be110…
Force block
— not fired
Score recovered
no
Elapsed
18.8s