JSON Viewer Plus - 20+ Themes & Auto Formatter
fgnmljinfladobclgacflibolhgpcdpc
Risk Score
5.09
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy on unrelated domain (httpfy.io ≠ cloudaid.net), admits data collection and 3rd-party sharing without extension-specific scope.
- webRequest + <all_urls> + content_scripts on all URLs gives broad passive surveillance capability over every site visited.
- No CSP on MV3 extension with broad host permissions raises injection-risk surface.
- No developer name listed; low install count (395) with high-tier permissions is a tail-attack-surface anomaly.
- small_install_high_perm anomaly flagged: 395 installs with HIGH-tier permissions warrants scrutiny.
Evidence
- privacy_policy_mismatch_domain store Privacy policy hosted at httpfy.io, not developer domain cloudaid.net; admits data_collection+third_party_sharing, scope_extension=false.
- webRequest_plus_all_urls manifest webRequest declared alongside host_permissions <all_urls> and content_scripts <all_urls> — full passive intercept capability.
- no_csp crx content_security_policy is null; MV3 provides some default but no explicit CSP hardening present.
- no_developer_name store developer_name is empty string; only email hello@cloudaid.net provided.
- install_perm_anomaly api install_perm_anomaly.small_install_high_perm=true with only 395 installs and HIGH-tier permissions.
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — no malicious code indicators found.
- no_bad_hosts_or_affiliates api threat_intel shows no bad_host_hits, affiliate_hits, or monetization_hits.
- developer_domain_resolves api cloudaid.net resolves and looks_throwaway=false; no operator siblings detected.
Permissions Breakdown
- activeTab low Scoped to user-initiated tab interaction only.
- storage low Local preference/theme storage; standard for formatter tools.
- clipboardWrite medium Can write to clipboard; appropriate for copy-JSON feature but misuse possible.
- webRequest high Can observe all network requests across all URLs; high surveillance potential.
- <all_urls> (host_permissions) high Full host access paired with webRequest and content_scripts — broad reach.
- content_scripts <all_urls> high JS injected into every page; can read/modify DOM on all sites.
Pillar Scores
Permissions6.50
Reputation6.50
Network4.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA
7c6ac3b3ac0e…
Force block
— not fired
Score recovered
no
Elapsed
23.4s