!StackOverflow
fohbkjbcfhdfefnhnjpnlbjjjknfejhh
Risk Score
4.03
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope data handling to this extension at all.
- Brand impersonation: 'stackoverflow' in name/description, developer is unaffiliated gmail user.
- Free-webmail developer (gmail), no business website, no verified publisher badge.
- Extension is 22 months stale (6-12mo band = +3.5; 12-24mo = +6.0 applied).
- No CSP declared (MV3 mitigates somewhat, but combined with stale age and generic policy raises concern).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[stackoverflow]; developer_domain=gmail.com; confirmed_owner=false.
- free_webmail_developer store developer_email=vincent.mughal77@gmail.com; no business website; not verified publisher.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true per classifier.
- stale_extension store months_since_update=22; last updated August 26, 2024; no changelog visible.
- no_csp manifest content_security_policy=null; csp_present=false; MV3 default applies but no explicit policy set.
- no_installs store installs field empty; no install count available; no ratings recorded.
- content_script_scope manifest content_scripts_matches=[https://*.stackoverflow.com/*]; narrow scope matching stated purpose.
- no_bad_hosts_or_cves crx cve_findings_raw=[], bad_host_hits=[], code_findings_raw=[], obfuscation_score=0.0; no malicious signals detected.
Permissions Breakdown
- content_scripts: https://*.stackoverflow.com/* low Scoped narrowly to stackoverflow.com; matches stated UI-enhancement purpose.
Pillar Scores
Permissions0.30
Reputation7.50
Network0.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA
7dedd61b4395…
Force block
— not fired
Score recovered
no
Elapsed
20.6s