Save as Shortcut
flehofiklehmnnolpjcamplcnmhgcbkk
Risk Score
4.82
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- last_updated is null/unknown — maintenance state cannot be assessed, defaulting to worst case.
- new Function() in bundled jszip.min.js is a code-execution risk if fed attacker-controlled input.
- No CSP declared (MV3 mitigates somewhat, but js_external_hosts include 5 distinct domains).
- Developer name missing; privacy policy not scoped to extension raises accountability gap.
Evidence
- privacy_policy_generic store Policy URL is Google's own account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true.
- maintenance_unknown store last_updated is empty string; months_since_update is null — treated as >36 months per conservative policy.
- function_constructor_in_jszip crx new Function() found in js/jszip.min.js; common in zip libraries but elevates code-quality risk.
- no_csp manifest content_security_policy is null; MV3 default helps but 5 external JS hosts noted.
- verified_publisher store verified_publisher=true; developer domain mythofechelon.co.uk resolves and is not throwaway.
- no_bad_hosts_no_affiliates api threat_intel shows empty bad_host_hits, affiliate_hits, and monetization_hits.
- no_cve_findings crx cve_findings_raw is empty; no known-vulnerable library versions detected.
- developer_name_missing store developer_name field is empty string; only email hello@mythofechelon.co.uk available.
Permissions Breakdown
- activeTab low Grants access to the current tab only on user action; limited scope.
- tabs medium Can read tab URLs and titles across all open tabs.
- contextMenus low Adds right-click menu items; low standalone risk.
- bookmarks medium Read/write access to user's full bookmark tree.
- storage low Local extension storage only; no cross-origin exposure.
- scripting medium Can inject scripts into pages; risk mitigated by no broad host_permissions.
Pillar Scores
Permissions2.90
Reputation2.00
Network2.00
Webstore1.00
Maintenance10.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA
234d6c9c67e6…
Force block
— not fired
Score recovered
no
Elapsed
23.2s