Just JSON Viewer
hpmmjcpbalflfgmgloddnkeibocfdjcn
Risk Score
5.17
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Abandoned: 38 months since last update, well past 36-month stale threshold.
- Privacy policy not scoped to this extension; data_collection field false but no retention disclosure.
- innerHTML DOM sink present and no CSP — XSS risk if JSON input is malicious.
- No developer name listed in store; reduces accountability.
- Install-URL opens herotofu.com onboarding page on install (minor hijack signal).
Evidence
- stale_extension store Last updated April 2023; 38 months since update triggers max maintenance score of 10.0.
- dom_sink_innerhtml_userctrl crx innerHTML sink in viewer JS; no CSP present, elevating XSS risk to +2.0 code quality.
- no_csp manifest MV3 extension; no content_security_policy declared. DOM sink risk amplified.
- privacy_policy_not_scoped api Policy fetched but scope_extension=false and no retention clause; scores +9.0 privacy.
- install_url_hijack crx onInstalled opens https://herotofu.com/extensions?chromeOnboarding=just-json-viewer (+2.0 webstore).
- no_developer_name store developer_name is empty string; +1.0 reputation penalty.
- no_bad_hosts_no_cves api threat_intel bad_host_hits and cve_findings_raw both empty; no CVE or threat-intel risk.
- developer_domain_resolves api herotofu.com resolves, not throwaway; partial reputation mitigation.
Permissions Breakdown
- activeTab low Grants access to the current tab only on user action; narrow scope.
- contextMenus low Adds right-click menu items; no data access on its own.
- scripting medium Can inject scripts into pages; paired with activeTab limits scope to user-triggered actions.
Pillar Scores
Permissions1.60
Reputation5.50
Network0.00
Webstore2.00
Maintenance10.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA
232437436c58…
Force block
— not fired
Score recovered
no
Elapsed
22.3s