CloudBoard - Online Code Editor and Compiler
kcghbbipihbbcjclnlmljpniibannhad
Risk Score
6.43
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Broad host permissions (http://*/*, https://*/*) allow content injection on every site, scope-mismatch vs stated code-editor function.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing (DoubleClick).
- Extension not updated in 36 months (maintenance score maxed); abandoned with elevated permissions is acquisition/compromise risk.
- Developer uses free Gmail address with no verified business domain; no verified publisher badge.
- Content script injected on https://chat.openai.com/* despite no AI/ChatGPT functionality stated — unexplained scope.
Evidence
- broad_host_permissions manifest host_permissions include http://*/* and https://*/* — full read/write access to all sites; mismatched to code-editor category.
- content_script_chatgpt manifest content_scripts_matches: ['https://chat.openai.com/*'] — unexplained injection on ChatGPT; not mentioned in description.
- generic_privacy_policy store Privacy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true per classification.
- monetization_hosts crx js_external_hosts includes stats.g.doubleclick.net (Google Ads) alongside two GA endpoints.
- stale_extension store Last updated June 2023; 36 months since update with broad permissions and 326 installs.
- free_webmail_developer store Developer email is cloudboard.live@gmail.com — free webmail, no verified publisher, no business domain resolved.
- install_perm_anomaly api small_install_high_perm=true, tail_attack_surface=true; 326 installs with HIGH-tier host permissions.
- featured_by_google store is_featured_by_google=true provides minor trust signal but does not override permission/privacy concerns.
Permissions Breakdown
- https://cloudboard.live/* low Scoped to developer's own domain; matches stated function.
- storage low Local storage only; no cross-origin data exfil risk on its own.
- http://*/* high Broad host permission covering all HTTP sites; enables content injection anywhere.
- https://*/* high Broad host permission covering all HTTPS sites; enables content injection anywhere.
Pillar Scores
Permissions6.50
Reputation6.50
Network4.00
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA
c0c12466b72a…
Force block
— not fired
Score recovered
no
Elapsed
21.0s