My Clipboard
emhmaepmgpjnimnogbehplipclejinpa
Risk Score
5.18
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but does NOT scope to this extension, admits data collection AND third-party sharing — worst-case policy (+10.0 privacy).
- Extension last updated 63 months ago (March 2021) — effectively abandoned, maintenance score 10.0.
- install_url_hijack flag is true; onInstalled may open a third-party URL.
- Developer name field is empty; reduced accountability.
- clipboardRead permission captures potentially sensitive clipboard contents with no scoped data-handling disclosure.
Evidence
- privacy_policy_scope_mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- maintenance_stale store 63 months since last update → maintenance pillar = 10.0.
- install_url_hijack crx install_url_hijack=true; target null but flag set — onInstalled opens external URL.
- developer_name_missing store developer_name is empty string; no 'Offered by' display name.
- verified_publisher store verified_publisher=true; discount applies but capped at -1.0 due to staleness >18mo (invariant 0c).
- no_csp crx content_security_policy is null; MV3 strict default applies, no v2 penalty.
- cve_findings_empty crx No CVEs detected; cve_pillar_score = 0.0.
- code_findings_empty crx No malicious code signals; obfuscation_score=0.0; code_quality = 0.0.
Permissions Breakdown
- storage low Stores clipboard data locally; expected for this category.
- clipboardRead medium Reads clipboard contents; core function but sensitive data exposure risk.
Pillar Scores
Permissions2.30
Reputation3.50
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA
a4c145e7e663…
Force block
— not fired
Score recovered
no
Elapsed
19.2s