Github Profile
eijnkinhnplaekpllmgbbfieecdhcmcp
Risk Score
6.74
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Extension abandoned 51 months ago (>36mo stale, MV2, no CSP) — maximum maintenance risk.
- Privacy policy is generic Google account policy: admits data collection + 3rd-party sharing without extension scope.
- Brand impersonation: mentions 'github' but developer is unaffiliated gmail user.
- No CSP + MV2 + innerHTML sinks in both content_script and vendor.js — XSS surface unmitigated.
- webRequest on github.com by unverified dev with no privacy policy and 6 external JS hosts including Heroku/Vercel badges.
Evidence
- maintenance_stale store Last updated May 2022; 51 months stale — >36mo bracket scores 10.0 on maintenance pillar.
- privacy_generic_google_policy crx Privacy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — scores 10.0.
- brand_impersonation store brand_mention.is_impersonation=true for 'github'; developer is gmail, confirmed_owner=false.
- no_csp_mv2 manifest MV2 + csp_present=false: +2.0 Network per v2 calibration; DOM sinks unmitigated.
- dom_sink_innerhtml crx Two innerHTML sinks (content_script.js, vendor.js) with no CSP and no eval — each scores +2.0 under FIX B.
- small_install_high_perm store install_perm_anomaly: 10 installs, HIGH-tier webRequest + broad host permission — tail attack surface flag.
- external_js_hosts crx 6 external JS hosts: heroku, vercel, github, reactjs.org, laobi.icu; 2 countries (HK, US).
- free_webmail_dev store Developer email moonrailgun@gmail.com; no verified publisher, no business website — Reputation floor 7.5.
Permissions Breakdown
- https://*.github.com/* high Broad host access to all github.com subdomains; enables content script injection and data read.
- webRequest high Can observe all network requests to github.com; combined with host access amplifies risk.
- content_scripts: https://github.com/* medium Injects JS into github.com pages; consistent with stated function but elevates DOM attack surface.
Pillar Scores
Permissions3.50
Reputation7.50
Network4.50
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:04
Listing SHA
a3811747882d…
Force block
— not fired
Score recovered
no
Elapsed
—