Preact Developer Tools
ilcajpmogmhpliinlbcdebhbcanbghmd
Risk Score
4.09
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- Broad <all_urls> host permissions + content scripts on all pages despite dev-tools function.
- Last updated 15 months ago; moderate staleness for an extension with high host access.
- Not a verified publisher; marvinh.dev domain resolves but is individual dev, not recognized org.
- tail_attack_surface flagged: small install base (~8K) with HIGH-tier permissions.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar.
- host_permissions_broad manifest <all_urls> in host_permissions and content_scripts_matches; DeveloperTools discount applies (-1.5).
- maintenance_stale store 15 months since last update → +6.0 maintenance pillar (6-12mo bracket).
- is_featured_by_google store Featured badge present; -2.0 reputation discount applied.
- no_bad_hosts_or_cves crx bad_host_hits=[], cve_findings_raw=[], js_external_hosts=[], obfuscation_score=0.0.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true; 8K installs with high-tier permission.
- csp_present_mv3 manifest CSP: script-src 'self'; object-src 'self'. MV3 with strict CSP — no network penalty.
- operator_cluster_clean api sibling_count=0, no monetization/affiliate hits, domain resolves, looks_throwaway=false.
Permissions Breakdown
- scripting medium Can inject JS into pages; paired with <all_urls> increases reach significantly.
- storage low Local extension storage; no exfil risk on its own.
- <all_urls> (host_permissions) high Broad host access across all sites; enables scripting injection everywhere.
- <all_urls> (content_scripts) high Content scripts run on every page; broad reach for a dev-tools extension.
Pillar Scores
Permissions4.00
Reputation3.50
Network0.00
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA
2cf4434f1c54…
Force block
— not fired
Score recovered
no
Elapsed
21.1s