Note Everywhere
fjfoncfdjhdefjhknbaphionnognbnpl
Risk Score
4.67
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but admits data collection and third-party sharing without extension-specific scope — scores maximum privacy risk.
- Developer uses free Gmail address with minimal identity ('bv'); no business domain or verified publisher status.
- scripting + <all_urls>: extension can inject JS into every page the user visits.
- install_url_hijack and uninstall_url_hijack flags present; targets are null but flag indicates hook is in place.
- No CSP present on MV3 extension with external JS host (react.dev) referenced.
Evidence
- privacy_policy_admits_3rd_party_sharing_no_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- free_webmail_developer store Developer email takumibv@gmail.com, name 'bv' — free webmail, no business domain; reputation floor >=7.5 per rubric.
- scripting_plus_all_urls manifest scripting permission combined with <all_urls> host permission enables arbitrary JS injection on any site.
- install_uninstall_url_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets null so no confirmed 3rd-party redirect, but hooks present.
- no_csp manifest content_security_policy is null; MV3 has strict default but explicit CSP absent; external host react.dev referenced.
- featured_by_google store is_featured_by_google=true; partial trust signal applied to reputation.
- no_bad_hosts_no_cves api bad_host_hits=[], cve_findings_raw=[], obfuscation_score=0.0, code_findings_raw=[] — no active malicious indicators.
- recently_updated store months_since_update=1; maintenance pillar=0.0.
Permissions Breakdown
- storage low Core for saving notes; low risk.
- unlimitedStorage low Extended quota for note data; low risk.
- scripting high Can inject JS into any page via <all_urls>; high capability risk.
- tabs medium Can read tab URLs and metadata; moderate privacy risk.
- contextMenus low Adds right-click menu entries; minimal risk.
- <all_urls> (host_permission) high Broad access to all sites; combined with scripting, can read/modify any page.
Pillar Scores
Permissions6.00
Reputation7.00
Network0.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA
4cc5c6438390…
Force block
— not fired
Score recovered
no
Elapsed
22.6s