intentleads - Engagement based LinkedIn Leads PREVIEW
kjidkkncdchjnnfpclneimlcmghcfoon
Risk Score
3.04
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Free-webmail dev (gmail) with no business developer name raises accountability concerns.
- Brand impersonation flag: mentions LinkedIn but developer is not affiliated with LinkedIn.
- webRequest on LinkedIn can observe all profile/feed network traffic including sensitive data.
- Small install base (40) with HIGH-tier permission (webRequest) is a tail-attack-surface signal.
- Privacy policy third_party_silence=true: third-party sharing not explicitly addressed.
Evidence
- free_webmail_dev store Developer email chrismeinl98@gmail.com; no verified business name listed.
- brand_impersonation store LinkedIn mentioned in title/description; developer domain gmail.com, confirmed_owner=false, is_impersonation=true.
- verified_publisher store verified_publisher=true; applies -3.0 reputation discount capped at floor 2.0 per free-webmail rule.
- install_perm_anomaly api 40 installs with webRequest (HIGH-tier); small_install_high_perm=true.
- privacy_third_party_silence api privacy_policy_classification.third_party_silence=true; third-party sharing not addressed.
- clean_code crx code_findings_raw empty, obfuscation_score=0.0, cve_findings_raw empty; no malicious signals.
- host_scope_narrow manifest Host permissions limited to *://*.linkedin.com/*; not broad cross-site.
- maintenance_3_to_6_months store months_since_update=6; boundary of 3-6mo band, +1.5 applied.
Permissions Breakdown
- activeTab low Scoped to user-initiated tab interaction; limited blast radius.
- webRequest high Can observe all network requests on matched hosts; significant surveillance capability.
- storage low Local data persistence; low direct risk.
- tabs medium Can read tab URLs and titles; metadata exposure risk.
- unlimitedStorage low Allows large local storage; no direct exfil risk.
- *://*.linkedin.com/* medium Broad host access scoped to LinkedIn only; justified by stated function.
Pillar Scores
Permissions4.50
Reputation7.00
Network0.00
Webstore5.00
Maintenance1.50
Privacy1.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 15:12
Listing SHA
e2ab12fc4ef4…
Force block
— not fired
Score recovered
no
Elapsed
—