JSON Formatter
jjkimejmneecdeiijfnakkokbplconhf
Risk Score
2.32
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Content script on <all_urls> injects into every site with no CSP, amplifying DOM-XSS risk.
- Two innerHTML-from-variable sinks found; no CSP to mitigate XSS escalation.
- Privacy policy discloses data collection and third-party sharing without retention period.
- No developer display name listed; low install count limits trust signal.
- MV3 + no CSP: network pillar +2.0 applied per v2 calibration rule (b).
Evidence
- content_scripts_matches=<all_urls> manifest Extension injects into every URL; +2.0 HIGH permission for broad host access.
- no_csp manifest content_security_policy is null; MV3+no CSP triggers +2.0 network penalty.
- dom_sink_innerhtml_userctrl x2 crx innerHTML sinks in chunks/meta.js and content.js; no CSP present, raising code quality score.
- privacy_policy_classification api Policy scoped to extension, data_collection=true, third_party_sharing=true, retention=false → +2.0.
- verified_publisher+featured store Verified publisher and featured badge; reputation hard-floored at 2.0 per v2 rule 0a.
- no_developer_name store developer_name is empty string; minor reputation concern offset by verified publisher.
- threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves, not throwaway.
- cve_findings_raw_empty crx No CVEs detected in bundled libraries; CVE pillar = 0.0.
Permissions Breakdown
- storage low Stores user preferences locally; minimal risk.
- content_scripts:<all_urls> high Injects scripts on all URLs; broad DOM access across every site visited.
Pillar Scores
Permissions3.30
Reputation2.00
Network2.00
Webstore0.00
Maintenance0.00
Privacy2.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA
711ec3daa10a…
Force block
— not fired
Score recovered
no
Elapsed
21.2s