Pomodoro Chrome Extension
iccjkhpkdhdhjiaocipcegfeoclioejn
Risk Score
1.96
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Privacy policy discloses third-party sharing without scoping to this extension or disclosing retention.
- new Function() constructor present in bundled webpack code; low-impact given narrow permissions.
- No developer display name on store listing reduces accountability.
- No CSP declared (MV3 default enforced, but external hosts fonts.googleapis.com and tailwindcss.com loaded).
- Maintenance: 11 months since last update approaching stale threshold.
Evidence
- verified_publisher + featured store Extension is verified publisher AND featured by Google; reputation floor applied at 2.0.
- privacy_policy third_party_sharing=true, retention=false api Policy scoped to extension, data_collection=true, third_party_sharing=true, no retention clause.
- function_constructor in webpack bundle crx new Function() found in iframe.js; likely webpack globalThis shim, not user-controlled input.
- no bad_host / affiliate / monetization hits api threat_intel shows empty bad_host_hits, affiliate_hits, monetization_hits.
- external JS hosts crx fonts.googleapis.com and tailwindcss.com referenced; standard CDN, not threat-intel flagged.
- cve_findings_raw empty crx No CVEs detected in bundled libraries (vue 3.5.15 clean).
- no developer display name store developer_name is empty string; reduces accountability signal.
- months_since_update=11 store Updated July 2025; 6-12 month band adds +3.5 to maintenance pillar.
Permissions Breakdown
- storage low Stores local timer settings; no data exfil risk alone.
- alarms low Schedules Pomodoro intervals; no user-data access.
Pillar Scores
Permissions0.60
Reputation2.00
Network0.00
Webstore1.00
Maintenance3.50
Privacy2.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA
838d73e0d27f…
Force block
— not fired
Score recovered
no
Elapsed
20.3s