Speed Reading
ihbdojmggkmjbhfflnchljfkgdhokffj
Risk Score
4.72
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing without scoping to this extension (worst-case privacy score).
- Free-webmail developer (gmail) with no named developer — accountability gap.
- scripting + <all_urls> + content_scripts on all URLs gives full read/write access to every page.
- CSP connect-src includes amplitude.com, sentry.io, logflare.app — analytics/logging on all browsing sessions.
- Months since update = 18 — borderline stale; verified publisher cap may not fully apply.
Evidence
- broad_host_access manifest host_permissions <all_urls> + content_scripts *://*/* — extension runs on every page the user visits.
- privacy_policy_classification api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → worst-case: admits sharing without scoping.
- free_webmail_developer store developer_email=azadev.team@gmail.com, developer_name empty; no verified business identity beyond publisher badge.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; partially mitigates reputation concern.
- csp_connect_src_analytics crx CSP connect-src allows amplitude.com, sentry.io, logflare.app — telemetry endpoints active on all sites.
- geo_diversity api JS hosts span 4 countries (CA, IN, SG, US); +1.5 network penalty for non-VPN/translation category.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; no malicious code signals detected.
- maintenance_borderline store months_since_update=18; exactly at 18mo boundary — verified-publisher cap applies but staleness noted.
Permissions Breakdown
- storage low Stores user preferences locally; low standalone risk.
- contextMenus low Adds right-click menu items; minimal risk.
- scripting high Programmatic script injection into pages; HIGH when combined with <all_urls>.
- <all_urls> (host_permission) high Broad host access across every site; enables reading/modifying all page content.
- *://*/* (content_scripts) high Content script injected on all URLs; REACH across every page visited.
Pillar Scores
Permissions5.50
Reputation5.50
Network3.50
Webstore1.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA
47306f695102…
Force block
— not fired
Score recovered
no
Elapsed
21.1s