L.O.C
eojdckfcadamkapabechhbnkleligand
Risk Score
4.97
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — worst-case disclosure.
- cookies + broad Facebook/Messenger host_permissions enables Facebook session-token exfiltration.
- Developer uses free Gmail address with empty developer_name field; low accountability.
- install_url_hijack fires on install, redirecting users to loc.dev/dashboard — unsolicited navigation.
- Extension is 25 months stale with 300K installs; abandoned high-reach tool is an acquisition target.
Evidence
- privacy_policy_admits_third_party_sharing_unscoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0 (v3.5 rule D).
- cookies_with_broad_facebook_host manifest cookies permission + https://*.facebook.com/* + https://*.messenger.com/* enables full session-cookie access.
- install_url_hijack crx install_url_hijack=true; onInstalled opens https://loc.dev/dashboard — unsolicited redirect on install (+2.0 Webstore).
- free_webmail_no_developer_name store developer_email=locmai88@gmail.com, developer_name empty; free-webmail+no-name reputation floor applies.
- stale_25_months store months_since_update=25; falls in 24-36mo band → Maintenance +8.5 before cap at 6.0 for MV3.
- verified_publisher_with_stale_and_gmail store verified_publisher=true but months>18 and dev domain is gmail; v3.5 invariant 0c caps discount at -1.0.
- lnmai_com_unknown_third_party manifest host_permissions include lnmai.com and mtfb.lnmai.com; no public identity; js_external_hosts confirms outbound reach.
- no_csp manifest csp_present=false on MV3; v2 fix (b) applies +2.0 Network only for MV2; MV3 strict default mitigates.
Permissions Breakdown
- notifications medium Can push notifications to user; medium nuisance/phishing vector.
- cookies high Can read/write cookies for host_permissions domains (Facebook, messenger).
- storage low Local extension storage only.
- unlimitedStorage low Allows large local data; minor risk alone.
- declarativeNetRequest medium Can block/redirect network requests; paired with host permissions raises concern.
- https://*.messenger.com/* high Broad host access to Messenger; cookies permission amplifies session-theft risk.
- https://*.facebook.com/* high Broad host access to Facebook; cookies permission amplifies session-theft risk.
- https://loc.dev/* low Developer's own domain; expected for update/config calls.
- https://lnmai.com/* medium Third-party domain with no clear public identity; unknown purpose.
- https://mtfb.lnmai.com/* medium Subdomain of lnmai.com; unclear purpose, Facebook-like naming pattern.
Pillar Scores
Permissions6.50
Reputation7.00
Network3.50
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:31
Listing SHA
62ce937a0652…
Force block
— not fired
Score recovered
no
Elapsed
27.3s