Search G. Calendar Tasks (By Natfluence)
hbbihbhfopbfekplgcaoaacnhpjdkbdf
Risk Score
4.52
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL returned HTTP error (fetch_error) — policy content unverifiable; privacy pillar scores maximum.
- Brand impersonation: 'google' mentioned in title/name but developer is not a confirmed Google owner.
- No CSP declared (MV3 popup) and innerHTML DOM-XSS sink found in popup.js.
- identity + identity.email permissions allow OAuth token acquisition and email read — significant if extension is ever compromised.
- Months since update = 17; approaching stale threshold with unresolved privacy policy fetch failure.
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError); privacy pillar capped at 10.0.
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[google]; confirmed_owner=false; verified_publisher=true → +1.0.
- dom_xss_sink crx popup.js: innerHTML assigned from variable; no CSP present → dom_sink_innerhtml_userctrl scores +2.0 (FIX B).
- no_csp manifest content_security_policy=null; MV3 has strict default but no explicit CSP declared.
- identity_permissions manifest identity + identity.email grant OAuth token and email address access to Google services.
- external_js_hosts crx js_external_hosts: dexie.org, fontawesome.com, tinyurl.com, www.apache.org — 4 distinct domains, country_count=2.
- maintenance_stale store months_since_update=17; scores +6.0 (6-12mo band exceeded; 17mo = 12-24mo band).
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; partial reputation discount applied.
Permissions Breakdown
- alarms low Schedules background tasks; minimal privacy risk.
- identity medium OAuth token access; can authenticate as user against Google APIs.
- identity.email medium Reads the signed-in user's email address via identity API.
- storage low Local extension storage only.
- unlimitedStorage low Allows larger local storage quota; no network risk on its own.
Pillar Scores
Permissions2.30
Reputation4.50
Network3.50
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA
c5cc53644526…
Force block
— not fired
Score recovered
no
Elapsed
23.9s