CSS Peek: Element Inspector
kfmdddceeniapmonignkaflhpidamhig
Risk Score
4.22
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — does not scope to this extension at all; admits data collection and 3rd-party sharing.
- Content script injected on <all_urls> gives broad per-page DOM access on every site visited.
- Gmail developer with no business domain; identity unverifiable.
- No CSP declared (MV3 default applies, but no explicit policy recorded) alongside broad content-script reach.
- Libraries detected (react, lodash, jszip) at unknown versions; CVE exposure unverifiable.
Evidence
- content_scripts_matches=<all_urls> manifest Content script injected on every URL; broad DOM read capability despite narrow declared permissions.
- privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- developer_email_gmail store Developer uses free Gmail address with no registered business domain; identity unverifiable.
- is_featured_by_google=true store Google Featured badge provides partial trust signal; applied -2.0 reputation discount.
- js_libraries_unknown_version crx react, react-dom, lodash, lodash-es, jszip detected via sourcemap; versions unknown — CVE check inconclusive.
- no_bad_hosts_no_affiliate api threat_intel shows no bad/affiliate/monetization hits; external hosts limited to github.com, react.dev.
- obfuscation_score=0.0_code_findings_empty crx No obfuscation detected; code_findings_raw empty; code quality pillar scored 0.
- months_since_update=4 store Updated Feb 2026; 4 months ago — maintenance penalty +1.5 (3-6 month band).
Permissions Breakdown
- activeTab low Scoped to user-activated tab; minimal reach without broad host access.
- downloads medium Can initiate file downloads; enables asset/export feature but adds surface.
- storage low Local settings persistence only; no network exfil path by itself.
- content_scripts:<all_urls> high Injects JS into every page the user visits; broad content-script reach.
Pillar Scores
Permissions4.50
Reputation6.50
Network2.00
Webstore1.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA
9973af662d8c…
Force block
— not fired
Score recovered
no
Elapsed
21.3s