React Developer Tools
fmkadmapgofadopljbjfkapdkoienihi
Risk Score
2.07
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; collects+shares data per policy.
- <all_urls> host permission with content_scripts on every site creates broad code-injection surface.
- new Function() constructor in worker file enables dynamic code execution; low obfuscation mitigates.
- developer_domain_info.looks_throwaway flagged for fb.com (likely false-positive heuristic, but noted).
- No verified-publisher badge; Meta identity unverified by Chrome Web Store.
Evidence
- broad_host_permissions manifest host_permissions: [<all_urls>] + content_scripts on <all_urls>; justified for DevTools but maximum site reach.
- function_constructor_in_worker crx new Function() in build/importFile.worker.worker.js; isolated to file-import worker, likely for CommonJS module shim.
- generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- featured_by_google store is_featured_by_google=true; follows recommended practices badge reduces but doesn't eliminate risk.
- recognized_org_meta store developer_name=Meta, email=extensions@fb.com; fb.com resolves; high-capability gate applies (broad host+scripting).
- no_bad_hosts_no_cves crx bad_host_hits=[], affiliate_hits=[], monetization_hits=[], cve_findings_raw=[]; clean threat-intel.
- csp_present_mv3 manifest CSP: script-src 'self'; object-src 'self'. MV3 strict default; no remote script-src.
- js_external_hosts crx External hosts in source: bugs.chromium.org, foo.com, react.dev — appear as reference URLs, not active fetch endpoints.
Permissions Breakdown
- scripting medium Allows JS injection into pages; core to DevTools function but broad capability.
- storage low Local preference/state storage; low risk.
- tabs medium Access to tab URLs and metadata; needed for DevTools targeting.
- <all_urls> (host_permissions) high Content scripts on all URLs; justified for a DevTools extension but broad reach.
Pillar Scores
Permissions4.50
Reputation3.00
Network0.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Scoring History
| sssiednfb8afc2cdp727562726963xsx | 2.54 | Low | review | 2026-09-05 |
| fsssiedxn8a28e0c8za xx pn8a28e0c8zsssiedx | 1.63 | Low | review | 2026-08-25 |
| sssiedne7081620dp727562726963xsx | 2.65 | Low | review | 2026-08-25 |
| v3.69968/"();}]9492 | 1.43 | Low | review | 2026-08-05 |
| v3.6"onmouseover=PjbZ(97422)" | 1.72 | Low | review | 2026-08-05 |
| bfgx3338%C0%BEz1%C0%BCz2a%90bcxhjl3338 | 1.58 | Low | review | 2026-08-05 |
| <th:t="${dfb}#foreach | 1.49 | Low | review | 2026-08-05 |
| v3.6&n959136=v976912 | 2.54 | Low | review | 2026-08-05 |
| v3.6'"()&%<zzz><ScRiPt >4JCY(9918)</ScRiPt> | 1.43 | Low | review | 2026-07-29 |
| v3.6&n971500=v972544 | 1.58 | Low | review | 2026-07-29 |
| v3.6 | 2.07 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA
b75b6a467036…
Force block
— not fired
Score recovered
no
Elapsed
50.8s