ShortURL.pt - Gerar URL reduzido (gratuito)
kcffejiafhmhliiemlmmonfildnhjhhb
Risk Score
3.35
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension at all; admits data collection and 3rd-party sharing.
- No developer name, email, or store metadata available — identity unverifiable.
- Extension contacts external host shorturl.pt; all URL shortening requests pass through this third-party service.
- No CSP declared (MV3 default applies but no explicit policy).
- months_since_update unknown — maintenance state cannot be assessed.
Evidence
- privacy_policy_generic store Policy URL is Google account privacy page — scope_extension=false, data_collection=true, third_party_sharing=true.
- no_developer_identity store developer_name and developer_email both missing; no verified publisher or featured badge.
- external_host crx js_external_hosts=['shorturl.pt']; all URLs processed by this third-party domain.
- permissions_minimal manifest Only activeTab + clipboardWrite declared; no host_permissions or content_scripts.
- no_cve_findings crx cve_findings_raw empty; no known vulnerable libraries detected.
- no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 2 JS files scanned cleanly.
- maintenance_unknown store months_since_update=null; last_updated missing; cannot assess staleness.
- operator_cluster_clean api sibling_count=0; no related extensions under same fingerprint.
Permissions Breakdown
- activeTab low Only accesses current tab on explicit user action; scoped and low risk.
- clipboardWrite medium Can write to clipboard; appropriate for a URL shortener but grants write access.
Pillar Scores
Permissions0.60
Reputation7.00
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:59
Listing SHA
daa7e79fb24c…
Force block
— not fired
Score recovered
no
Elapsed
—