Calendar Plus
kgbbebdcmdgkbopcffmpgkgcmcoomhmh
Risk Score
4.36
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Brand impersonation flag: extension mentions 'google' in brand_mention but developer is not a verified Google entity.
- No CSP on MV3 extension; innerHTML DOM-XSS sink present in bundled React code without CSP mitigation.
- Last updated 15 months ago — approaching stale threshold; no changelog visible.
- No developer name declared; identity tied only to patii.uk domain email.
Evidence
- privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar (v3.5 rule D).
- brand_impersonation store brand_mention.is_impersonation=true; mentions 'google' brand; developer is verified_publisher so +1.0 reputation (v3.2 rule 9).
- dom_sink_innerhtml crx dom_sink_innerhtml_userctrl in dist/main.bundle.js; no CSP present → elevated to +2.0 code quality (FIX B).
- no_csp manifest content_security_policy is null on MV3; does not trigger MV2+no-CSP bonus but leaves innerHTML sink unmitigated.
- maintenance_stale store months_since_update=15; falls in 12-24 month band → +6.0 maintenance pillar.
- verified_publisher store verified_publisher=true and is_featured_by_google=true; discount capped at -1.0 per invariant 0c (months_since_update>12 threshold not triggered at 15mo but >18mo cap not reached).
- no_developer_name store developer_name is empty string; +1.0 reputation for missing 'Offered by' name.
- content_script_scope manifest content_scripts scoped to calendar.google.com only — narrow, matches stated function; no broad host permissions declared.
Permissions Breakdown
- identity low OAuth token access; low risk without broad scopes declared.
- storage low Local extension storage only; no cross-site data risk.
- content_scripts: https://calendar.google.com/calendar/u/0/r/* medium Script injected into Google Calendar pages; scoped to one domain but can read calendar data.
Pillar Scores
Permissions1.30
Reputation5.50
Network2.00
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA
b8a494850756…
Force block
— not fired
Score recovered
no
Elapsed
24.7s