Distraction Free for LinkedIn™
kigfnbfbpfpgphbocdkmeablbgdbpfke
Risk Score
3.52
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension at all; data collection and 3rd-party sharing admitted without extension context.
- Brand impersonation: 'LinkedIn™' in name, developer is not LinkedIn; confirmed non-owner with free-webmail email.
- Developer uses gmail.com with no verified business domain, reducing accountability.
- Featured by Google offsets some risk but developer identity remains unverifiable.
- Content script on LinkedIn DOM can read sensitive professional data despite narrow scope.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands=['linkedin'], confirmed_owner=false, dev domain=gmail.com.
- generic_privacy_policy store Privacy policy is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email matt.thurmond@gmail.com; no verified business domain.
- featured_by_google store is_featured_by_google=true; provides partial reputation credit.
- content_script_scope manifest content_scripts_matches=['https://www.linkedin.com/*']; narrowly scoped.
- no_permissions manifest permissions=[], host_permissions=[]; only content script host access declared.
- clean_code crx code_findings_raw=[], obfuscation_score=0.0, 2 JS files scanned; no malicious patterns.
- maintenance store months_since_update=8; 3-6 month band (+1.5).
Permissions Breakdown
- content_scripts: https://www.linkedin.com/* medium Scoped to LinkedIn only; can read/modify LinkedIn page content.
Pillar Scores
Permissions1.00
Reputation6.50
Network0.00
Webstore2.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA
61b0f763f4cc…
Force block
— not fired
Score recovered
no
Elapsed
18.4s