Cat Gatekeeper
elbikiflgfhjdjmficnigpeegjbhdidh
Risk Score
4.19
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Content scripts run on all HTTP/HTTPS pages giving broad page access despite minimal declared permissions.
- Developer uses free Gmail address with no verified business identity or named developer.
- Privacy policy hosted on GitHub Pages, scope_extension=false and data_collection=false — generic, unscoped.
- No CSP defined (MV3 so no +2.0 network penalty, but no additional hardening).
- last_updated is missing — maintenance posture unknown, cannot rule out abandonment.
Evidence
- broad_content_scripts manifest content_scripts_matches covers http://*/* and https://*/* — injected on every page visited.
- verified_publisher store verified_publisher=true; mitigates reputation concern but dev identity is still gmail-only.
- free_webmail_dev store developer_email=zokuzoku.app@gmail.com; no business domain; no developer_name field.
- privacy_policy_unscoped api Policy fetched but scope_extension=false, data_collection=false — does not describe this extension.
- no_last_updated store last_updated is empty string; maintenance posture cannot be assessed, defaulting to unknown.
- no_cve_no_bad_hosts crx cve_findings_raw empty, bad_host_hits empty, affiliate_hits empty — no threat-intel signals.
- code_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — clean scan.
- install_count_high store 200,000 installs increases blast radius of any future compromise.
Permissions Breakdown
- storage low Used to persist extension settings locally; minimal risk.
- content_scripts http://*/* https://*/* high Broad content script injection on all HTTP/HTTPS pages; significant reach.
Pillar Scores
Permissions3.50
Reputation6.50
Network2.00
Webstore2.00
Maintenance5.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA
621fcbdcb7e8…
Force block
— not fired
Score recovered
no
Elapsed
20.1s