Vector Vault
faedpdgepbjjlmeiiapjflihlbcppdhg
Risk Score
3.17
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Google's generic privacy policy is not scoped to this extension; data handling for user credentials is undisclosed.
- Free-webmail developer (gmail) with no developer name or verified business identity.
- Password manager accessing clipboard and injecting scripts — high-value target if compromised.
- No privacy policy scoped to this extension despite handling authentication credentials.
- Very low install count (6) makes reputation signals unreliable; unproven in the wild.
Evidence
- privacy_policy_generic store Privacy policy URL points to Google's own account policy, not scoped to this extension or its data handling.
- free_webmail_dev_no_name store Developer email zerovectorti@gmail.com; developer_name is empty; no verified business identity.
- no_code_findings crx 2 JS files scanned; code_findings_raw empty; obfuscation_score 0.0 — no malicious indicators detected.
- host_permission_scoped manifest Single host permission vault.umbrellacloud.com.br; no broad host access; geo: CA only.
- no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.
- no_bad_hosts api threat_intel bad_host_hits, monetization_hits, and affiliate_hits all empty.
- privacy_policy_admits_third_party store Fetched policy has data_collection=true, third_party_sharing=true but scope_extension=false — v3.5(D) applies: +10.0.
- mv3_no_csp manifest Manifest version 3 with no explicit CSP; MV3 enforces strict default so no +2.0 MV2 penalty applies.
Permissions Breakdown
- storage low Standard local data persistence; low risk for a password vault extension.
- activeTab medium Accesses current tab on user action; needed for auto-fill but limited to active tab only.
- scripting medium Can inject scripts into pages; necessary for auto-fill but elevates capability.
- clipboardWrite medium Can write to clipboard; expected for password managers copying credentials.
- https://vault.umbrellacloud.com.br/* medium Scoped host access to single vault domain; appropriate for a password vault fetching credentials.
Pillar Scores
Permissions2.30
Reputation7.00
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 11:41
Listing SHA
8d35b2517449…
Force block
— not fired
Score recovered
no
Elapsed
—