memo
iebchnlkmillogldhnljpmmnpaoniopm
Risk Score
4.87
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension not updated in 40 months (>36mo stale) — abandoned, no security patches.
- Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
- Developer uses free Gmail account with no verified business identity.
- No content security policy (MV3 default applies but no explicit CSP set).
- Very low install base (262) limits blast radius but also means no community vetting.
Evidence
- maintenance_stale store Last updated Feb 2023, 40 months ago — exceeds 36-month stale threshold (+10.0 maintenance).
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D rule).
- developer_identity store Developer email is free Gmail (Ia1stmonster009@gmail.com); no business website; reputation starts 5.0+1.5=6.5.
- permissions_minimal manifest Only 'storage' declared; no host permissions, no content scripts — very low capability surface.
- no_cve_no_code_findings crx cve_findings_raw empty, code_findings_raw empty, obfuscation_score=0.0 — code quality clean.
- is_featured_by_google store Extension carries 'Featured' badge — partial trust signal offsetting some reputation concern.
- threat_intel_clean api No bad_host_hits, affiliate_hits, monetization_hits, or sibling extensions detected.
- no_external_hosts crx js_external_hosts empty, host_geo_diversity country_count=0 — no outbound network surface.
Permissions Breakdown
- storage low Needed to persist notes locally; no cross-origin or sensitive data access.
Pillar Scores
Permissions0.30
Reputation6.50
Network0.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA
0af146079ae9…
Force block
— not fired
Score recovered
no
Elapsed
18.2s