DNS Lookup
ekbgejcpgolcbfcaeapipnaoemoomcgf
Risk Score
4.49
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- 52 months since last update — abandoned extension with no security patches.
- Privacy policy fetch failed; treated as unfetched, maximum privacy risk score.
- new Function() constructor in app.js — dynamic code execution pattern present.
- No developer name listed; developer identity relies solely on email domain.
- No CSP defined (MV3 mitigates but absence still reduces defense-in-depth).
Evidence
- stale_extension store Last updated February 2022, 52 months ago. No updates for over 4 years.
- privacy_policy_fetch_failed api privacy_policy_classification.fetched=false due to fetch_error:HTTPError; scored as +10.
- function_constructor crx app.js contains new Function() constructor; matches debugger_attach/function_constructor signal +2.5.
- verified_publisher store Verified publisher badge present; -3.0 reputation discount applied, floored at 2.0.
- developer_domain_resolves api whatsmydns.net resolves, not throwaway; reduces identity risk.
- description_promise_mismatch store Description promises 'record' but lacks tabCapture/desktopCapture; +2.0 webstore.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
- no_bad_hosts api threat_intel bad_host_hits, affiliate_hits, and monetization_hits all empty.
Permissions Breakdown
- storage low Local storage for user preferences; no cross-site risk.
- activeTab low Scoped to current tab on user action only; limited capability.
Pillar Scores
Permissions0.60
Reputation2.00
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA
7b7a739eea99…
Force block
— not fired
Score recovered
no
Elapsed
19.2s