Qlock — Clock & Weather Widget
gofmkgiojdoglaogllgdamcgbjfedpfe
Risk Score
3.36
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy URL returns HTTP error (fetch_error:HTTPError) — policy content unverifiable, treated as unfetched.
- Developer uses free webmail (gmail.com) with no developer name listed, reducing accountability.
- Geolocation permission sends user IP to third-party geojs.io for location lookup.
- No CSP declared (MV3 mitigates but adds no explicit restriction on extension pages).
- Very low install count (82) limits trust signal; extension is essentially unvetted by community.
Evidence
- privacy_policy_fetch_failed api Privacy policy URL https://www.qlark.studio/qlok-privacy-policy/ returned fetch_error:HTTPError — classified as unfetched, score +10.0.
- free_webmail_dev store Developer email alexqlark.design@gmail.com is gmail.com; no developer name provided — reputation penalty applied.
- no_cve_findings crx cve_findings_raw is empty; no known vulnerable libraries detected.
- no_code_findings crx code_findings_raw is empty; obfuscation_score 0.0 — clean JS scan.
- verified_publisher store verified_publisher == true; partial reputation discount applied, but free-webmail floor raised score to 6.5.
- threat_intel_clean api bad_host_hits, affiliate_hits, monetization_hits all empty; developer_domain_info null.
- geolocation_third_party manifest host_permission https://get.geojs.io/* used for IP geolocation; user IP disclosed to third party on every use.
- recently_updated store months_since_update == 3; maintenance score 0.0.
Permissions Breakdown
- geolocation medium Accesses precise user location; justified for weather widget but sensitive.
- storage low Local data persistence; standard for widget settings.
- alarms low Periodic background wake; needed for clock/weather refresh.
- notifications low Can push desktop notifications; limited blast radius.
- https://get.geojs.io/* medium IP geolocation lookup endpoint; sends user IP to third party.
- https://api.open-meteo.com/* low Open-source weather API; no auth/PII required.
- https://geocoding-api.open-meteo.com/* low Geocoding for location names; open-meteo public service.
Pillar Scores
Permissions2.00
Reputation6.50
Network2.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA
0bbf15e4b0b4…
Force block
— not fired
Score recovered
no
Elapsed
24.1s