Privacy Settings
ijadljdlbkfhdoblhaedfgepliodmomj
Risk Score
4.62
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension last updated 50 months ago — abandoned, high takeover/drift risk.
- Developer uses free webmail (gmail.com) with no verified business identity.
- Privacy policy URL points to the Chrome Web Store listing page, not a real policy — generic/non-scoped.
- Uninstall URL hijack flag set; may redirect users on removal.
- tail_attack_surface true: small install base with a high-tier permission (privacy API).
Evidence
- stale_extension store Last updated April 2022; 50 months since update — maintenance score 10.0.
- free_webmail_developer store Developer email rynu.smith@gmail.com; no verified business domain.
- privacy_policy_inadequate store Privacy policy URL is the extension's own store listing; scope_extension=true but third_party_sharing=true, retention=true, data_collection=false.
- uninstall_url_hijack crx uninstall_url_hijack=true; chrome.runtime.setUninstallURL() to unknown target.
- tail_attack_surface api install_perm_anomaly: tail_attack_surface=true; 4,000 installs with privacy API permission.
- no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit policy declared.
- clean_code_scan crx code_findings_raw empty; obfuscation_score 0.0; no external JS hosts.
- no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.
Permissions Breakdown
- privacy high Grants access to Chrome privacy/content settings — core to stated function but powerful API.
- storage low Persists user preferences; low standalone risk.
- contextMenus low Adds right-click menu items; minimal risk.
Pillar Scores
Permissions2.50
Reputation6.50
Network0.00
Webstore2.50
Maintenance10.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA
3adba64e5955…
Force block
— not fired
Score recovered
no
Elapsed
18.3s