Crypto Tracker
jjfppgljnjgmkkbpkpbdbbdaleihgfnh
Risk Score
3.23
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- Developer uses free Gmail address with no verified business identity.
- Extension is featured by Google but developer accountability is low (Gmail dev, no domain).
- 3 external JS hosts (getbootstrap.com, github.com, webpack.js.org) referenced — verify these are CDN-only and not runtime code loads.
- Small install base (1,000) limits blast radius but reduces vetting signal.
Evidence
- no_declared_permissions manifest permissions[] and host_permissions[] are both empty; no HIGH/MEDIUM capabilities claimed.
- free_webmail_developer store Developer email kareem.ashraf.91@gmail.com is free webmail; no verified business website.
- generic_privacy_policy store Privacy URL points to Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true.
- is_featured_by_google store Extension carries Google Featured badge, providing partial vetting signal despite Gmail dev identity.
- csp_present_strict manifest CSP: script-src 'self'; object-src 'self'; — restrictive, no remote script sources allowed.
- no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 5/5 JS files scanned cleanly.
- external_js_hosts crx 3 external hosts in CSP/references: getbootstrap.com, github.com, webpack.js.org — likely doc links only.
- no_cve_findings crx cve_findings_raw is empty; no known-vulnerable libraries detected.
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore0.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA
004be2a96d70…
Force block
— not fired
Score recovered
no
Elapsed
16.6s