Auto Refresh Plus
ffejlioijcokmblckiijnjcmfidjppdn
Risk Score
2.47
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Broad <all_urls> host permission with content_scripts on every site — high REACH if compromised.
- Developer email is free-webmail (gmail) with no verified developer name; accountability gap.
- No developer name listed; verified_publisher badge partially offsets but gmail identity remains weak.
- js_external_hosts includes react.dev — external JS reference warrants scrutiny despite no bad-host hits.
- MV3 with no CSP declared; csp_present=false adds minor network risk but no code findings found.
Evidence
- host_permissions_all_urls manifest <all_urls> host permission paired with content_scripts on all URLs — maximum site reach.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; significant trust signals partially offset risks.
- developer_email_free_webmail store lukemartindev482@gmail.com — numbered-alias gmail, no developer name, no verified business identity.
- privacy_policy_scoped api Policy fetched, scope_extension=true, data_collection=true, retention=true, third_party_sharing=true — fully disclosed.
- code_findings_clean crx 0 code findings, obfuscation_score=0.0, 4 JS files scanned — no malicious patterns detected.
- cve_findings_empty crx No CVEs found in bundled libraries; no bad-host or monetization hits.
- js_external_host_react_dev crx js_external_hosts includes react.dev alongside autorefreshplus.in; no threat-intel hits on either.
- no_csp manifest csp_present=false on MV3; adds minor network surface but MV3 has strict defaults mitigating impact.
Permissions Breakdown
- storage low Stores user settings; low impact alone.
- <all_urls> (host_permissions) high Content scripts injected on every site; broad reach for page manipulation.
- <all_urls> (content_scripts_matches) high Script runs on every page load; high data access surface.
Pillar Scores
Permissions4.50
Reputation4.50
Network2.00
Webstore2.50
Maintenance0.00
Privacy0.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:10
Listing SHA
b3ec05f34d5e…
Force block
— not fired
Score recovered
no
Elapsed
—