Wide GitHub
kaalofacklcidaampbokdplbklpeldpj
Risk Score
3.57
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope to this extension, admits data collection and third-party sharing.
- Brand impersonation signal: extension mentions 'github' but developer domain is live.com, not github.com or a verified org.
- Developer email on live.com free webmail with no verified business domain.
- No CSP declared (MV3 default provides some protection, but no explicit policy).
- Content scripts on github.com/gist.github.com could read sensitive repo/code content if extension were compromised.
Evidence
- privacy_policy_generic api Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- brand_impersonation store brand_mention.is_impersonation=true, brands=[github], dev domain=live.com, not verified_publisher → +2.0 reputation.
- free_webmail_dev store Developer email xthexder@live.com is free-webmail without verified business website → +1.5 reputation.
- no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty; code quality = 0.0.
- narrow_host_permissions manifest Content scripts scoped to github.com and gist.github.com only; no broad host_permissions declared.
- clean_threat_intel api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain live.com resolves, not throwaway.
- recently_updated store Last updated May 18, 2026; months_since_update=1 → maintenance pillar = 0.0.
Permissions Breakdown
- content_scripts: https://gist.github.com/* medium Injects scripts into GitHub/Gist pages; scoped narrowly to stated function.
- content_scripts: https://github.com/* medium Injects scripts into GitHub pages; consistent with stated width-adjustment purpose.
Pillar Scores
Permissions2.00
Reputation6.50
Network0.00
Webstore3.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA
6bcc4d84534d…
Force block
— not fired
Score recovered
no
Elapsed
19.6s