Otto: Pomodoro timer & Website Blocker. Block sites, Focus mindfully
jbojhemhnilgooplglkfoheddemkodld
Risk Score
4.06
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing true — worst-case privacy posture (score +10.0).
- No CSP declared (MV3); innerHTML sinks in 8 files including contentScript running on <all_urls> elevate DOM-XSS risk.
- scripting + <all_urls> content_scripts allow arbitrary JS injection on every visited site.
- Privacy policy does not scope to this extension despite 60k users and broad host access.
- developer_name absent; identity anchored only to ottoapp.me email despite verified-publisher badge.
Evidence
- privacy_policy_scope_extension_false_with_collection_and_sharing api Policy fetched, length 101666; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5-D).
- no_csp_mv3 manifest content_security_policy is null; no CSP on MV3. innerHTML sinks in 8 JS files elevate XSS risk without mitigation.
- dom_sink_innerhtml_userctrl_multi crx 8 files contain innerHTML sinks (blockpage, contentScript, fanalytics, settingsPage, onboarding, autoblock, permaBlockpage, popup).
- function_constructor crx new Function() in background.bundle.js; standard React globalThis shim but still a dynamic code eval path.
- scripting_plus_all_urls manifest scripting permission + <all_urls> host + content_scripts on all URLs = full page JS injection capability.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; reputation floor 2.0 applied.
- threat_intel_clean api No bad_host_hits, affiliate_hits, monetization_hits, or review red flags detected.
- maintenance_current store Last updated May 8 2026; months_since_update=1 → maintenance score 0.0.
Permissions Breakdown
- action low UI toolbar button — no data access.
- alarms low Timer scheduling, matches stated Pomodoro function.
- storage low Local preference storage.
- declarativeNetRequest medium URL blocking; matches stated website-blocker function.
- tabs medium Can read tab URLs/titles across all tabs.
- notifications low User-facing Pomodoro alerts.
- offscreen low Background audio/timer use; low direct risk.
- unlimitedStorage low Extended local storage quota.
- scripting high Arbitrary JS injection into pages; broad with <all_urls>.
- activeTab low Scoped to user-activated tab only.
- <all_urls> (host) high Content scripts and scripting run on every site; high reach.
Pillar Scores
Permissions5.80
Reputation2.00
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA
49e73a335194…
Force block
— not fired
Score recovered
no
Elapsed
32.9s