Browser Time Setter
icigmcoimmojjbeojajeljahlfeldjad
Risk Score
3.72
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is generic Google account policy — does not scope to this extension at all (scope_extension=false, data_collection=true, third_party_sharing=true).
- Content scripts declared on <all_urls> — runs on every site the user visits despite minimal stated function.
- Free-webmail developer (gmail.com) with no business domain; no verified publisher badge.
- No CSP — MV3 default protections apply but absence still noted for DOM-injection risk.
- Very low install count (15) limits blast radius but also limits community vetting.
Evidence
- content_scripts_matches=<all_urls> manifest Content scripts injected on every URL despite extension being a dev/test time-setter utility.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_email_free_webmail store Developer email tor.henning@gmail.com; no business domain; not verified publisher.
- no_csp manifest content_security_policy is null; MV3 strict default partially mitigates but no explicit policy set.
- no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; no exfil or eval indicators detected.
- no_cve_findings crx cve_findings_raw empty; no vulnerable bundled libraries detected.
- maintenance_3-6mo store Last updated September 8 2025; ~9 months since update — in 3-6mo band (score +1.5).
- threat_intel_clean api bad_host_hits, affiliate_hits, monetization_hits all empty; single search engine google.com.
Permissions Breakdown
- activeTab low Access only to current tab on explicit user action; limited scope.
- scripting medium Can inject scripts into pages; risk elevated by content_scripts on <all_urls>.
- storage low Local extension storage only; no data exfil surface by itself.
- content_scripts:<all_urls> high Script runs on every page the user visits, broad reach even without explicit host_permissions.
Pillar Scores
Permissions3.30
Reputation6.50
Network0.00
Webstore1.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA
bc40bdb9f3fd…
Force block
— not fired
Score recovered
no
Elapsed
20.6s