My ToDo List
gpfjgnojlfaeolinkbpcjjomklilhfco
Risk Score
3.52
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; collects and shares data per policy terms.
- Developer uses free webmail (gmail.com) with no verified business identity.
- Extension is 12 months since last update — approaching stale territory.
- No content security policy defined (MV3 default mitigates but CSP absence noted).
- Low install base (785) limits confidence in community vetting.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
- developer_email_free_webmail store Developer email dheerajsahni890@gmail.com is free webmail; no verified business domain; +1.5 reputation.
- is_featured_by_google store Extension carries Google Featured badge; -2.0 reputation discount applied.
- maintenance_stale store months_since_update=12; falls in 6-12mo band → +3.5 maintenance.
- no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.
- no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; code quality = 0.0.
- no_host_permissions manifest host_permissions=[], content_scripts_matches=[]; no broad host access.
- no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty; network behavior = 0.0.
Permissions Breakdown
- storage low Standard local data persistence; no cross-origin access.
- unlimitedStorage low Extends storage quota only; no additional data access beyond storage.
Pillar Scores
Permissions0.60
Reputation6.50
Network0.00
Webstore0.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA
5a9328d75ed4…
Force block
— not fired
Score recovered
no
Elapsed
18.3s