Google Calendar Disable Month Scroll
fhcfmpoiniaamlhkcpiaahokbpibjjoh
Risk Score
5.14
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Abandoned: last updated May 2022 (49 months ago), no updates in >36 months.
- Brand impersonation: 'Google Calendar' in name, developer is unaffiliated gmail user.
- Privacy policy fetched but scope_extension==false; does not specify what this extension collects.
- Free-webmail developer (gmail) with no verified business website raises accountability concern.
- No CSP declared (MV3 mitigates but adds +2.0 Network via v2 calibration fix).
Evidence
- maintenance_stale store Last updated May 2, 2022; 49 months since update triggers max maintenance score of 10.0 + zombie booster check (installs 6k, <10k, no booster).
- brand_impersonation store brand_mention.is_impersonation=true, brands=['google'], confirmed_owner=false, developer_domain=gmail.com.
- privacy_policy_scope api Policy fetched but scope_extension=false, data_collection=false → +9.0 privacy per v3 FIX A.
- developer_email_webmail store Developer email raphael.schaad@gmail.com is free webmail; no verified business domain.
- no_csp manifest content_security_policy=null on MV3; +2.0 Network per v2 fix (b).
- is_featured_by_google store is_featured_by_google=true; applies -2.0 Reputation discount (Follows recommended practices).
- cve_findings_empty crx cve_findings_raw=[]; no CVE exposure.
- code_findings_empty crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[]; code quality score=0.0.
Permissions Breakdown
- content_scripts: https://calendar.google.com/* medium Scoped to calendar.google.com only; matches stated function of disabling scroll.
Pillar Scores
Permissions1.00
Reputation6.50
Network2.00
Webstore2.00
Maintenance10.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA
aeae58d780ac…
Force block
— not fired
Score recovered
no
Elapsed
19.5s