CSS Magic Inspector
iahmjmilfnadmhccnianabehncloidpe
Risk Score
5.75
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Generic Google privacy policy (scope_extension=false, data_collection=true, third_party_sharing=true) — policy admits 3rd-party sharing unrelated to this extension.
- Content script injected on <all_urls> with no CSP; broad reach for a 39-install dev tool with no business identity.
- Free-webmail developer (gmail), no developer name, no verified publisher — no accountability.
- Extension last updated 22 months ago; approaching abandonment threshold.
- install_perm_anomaly: small install base + high-tier permission = elevated tail-attack-surface risk.
Evidence
- privacy_policy_generic_google store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
- host_permissions_all_urls_content_script manifest content_scripts_matches=[<all_urls>] + host_permissions=[<all_urls>]; no CSP on MV3 extension.
- free_webmail_no_dev_name store developer_email=sureshraman87@gmail.com, developer_name empty, no verified_publisher.
- months_since_update store 22 months since last update; scores +6.0 on maintenance pillar (12–24 mo band).
- install_perm_anomaly api 39 installs + has_high_tier_permission=true; tail_attack_surface=true, small_install_high_perm=true.
- code_findings_clean crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[] — no malicious code indicators.
- threat_intel_clean api bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no threat-intel hits.
- cve_findings_empty crx cve_findings_raw=[] — no CVE exposure detected.
Permissions Breakdown
- activeTab low Grants access to the current tab only when user invokes the extension; limited scope.
- host_permissions: <all_urls> high Content script injected on all URLs; broad reach beyond stated developer-tool function.
Pillar Scores
Permissions5.50
Reputation7.50
Network2.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA
a49f4fa954f0…
Force block
— not fired
Score recovered
no
Elapsed
20.0s