JSON Viewer
gbdbademeighmnbliehmnoifmabbedbp
Risk Score
4.23
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Gmail-hosted dev with <all_urls> content script injection — no verified identity or business domain.
- Privacy policy is generic Google account policy (scope_extension=false, admits data collection and 3rd-party sharing) — scores maximum privacy risk.
- No content_security_policy on MV3 extension with broad host access increases DOM-sink risk surface.
- Free-webmail developer (softroyals@gmail.com) with no verifiable business entity.
- 6K installs with HIGH-tier permission and no accountability mechanism beyond a Gmail address.
Evidence
- host_permissions_all_urls manifest <all_urls> in host_permissions + content_scripts_matches; extension runs on every site the user visits.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening declared.
- generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email softroyals@gmail.com; brand_mention.developer_domain=gmail.com; no business site.
- no_bad_hosts_or_affiliates api threat_intel bad_host_hits, affiliate_hits, monetization_hits all empty; js_external_hosts empty.
- no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 4 JS files scanned, no exfil or eval indicators.
- no_cve_findings crx cve_findings_raw empty; js_libraries_detected empty; no known vulnerable bundled libs.
- maintenance_6_12mo store Last updated July 11 2025; months_since_update=11; falls in 6-12mo bracket (+3.5).
Permissions Breakdown
- activeTab low Grants access to current tab only on user interaction; scoped and temporary.
- storage low Local extension storage only; no cross-origin data access.
- <all_urls> (host_permissions) high Content scripts injected into every page; broad read access to all web content.
- <all_urls> (content_scripts_matches) high Script runs on every URL visited; high reach, especially without CSP.
Pillar Scores
Permissions4.50
Reputation6.50
Network2.00
Webstore0.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA
477620ec03fc…
Force block
— not fired
Score recovered
no
Elapsed
21.8s