Display LinkedIn Post Date and Time
hkgafbpgfpjjamcgkfdkdocppfpcjjhn
Risk Score
4.54
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Brand impersonation: extension name/function references LinkedIn without confirmed ownership, developer is unverified gmail user.
- Developer identity is a numbered-alias gmail account (mamaciel2022@gmail.com) with no business domain or verified publisher badge.
- description_promise.is_shell_pattern flagged true despite narrow permissions — warrants manual review.
- Maintenance at 12 months borderline stale; no changelog visible.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['linkedin']; developer_domain=gmail.com; confirmed_owner=false.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
- free_webmail_developer manifest developer_email=mamaciel2022@gmail.com; no business website; no verified publisher badge.
- shell_pattern_flag store description_promise.is_shell_pattern=true with mismatches=[]; low install count 4000.
- no_csp crx content_security_policy=null; MV3 so no +2.0 network penalty, but no CSP noted.
- content_scripts_scope manifest Content scripts scoped to 5 linkedin.com subpaths only — matches stated function.
- maintenance store months_since_update=12; falls in 6-12mo band (+3.5).
- no_code_findings crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[], cve_findings_raw=[] — clean scan.
Permissions Breakdown
- storage low Stores local settings only; no cross-origin data access.
- content_scripts: https://www.linkedin.com/* medium Injects JS into LinkedIn pages; scoped only to LinkedIn, matching stated function.
Pillar Scores
Permissions0.30
Reputation8.50
Network0.00
Webstore6.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA
c888e966b9d6…
Force block
— not fired
Score recovered
no
Elapsed
20.6s