Duplicate Tab Shortcut
klehggjefofgiajjfpoebdidnpjmljhb
Risk Score
4.22
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Nearly 3-year update stale (35 months) — zombie extension risk for 80K users.
- Privacy policy is Google's generic account policy; not scoped to this extension, admits data collection and third-party sharing.
- Free-webmail developer (gmail.com), no developer name or business identity disclosed.
- No CSP (MV3 so no v2 penalty, but no inline protection for any injected content).
- Verified publisher badge present but does NOT offset stale+unscoped-policy combo under v3.5 invariant 0c.
Evidence
- stale_extension store Last updated July 2023; 35 months since update triggers +8.5 maintenance score.
- generic_privacy_policy store Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
- free_webmail_dev manifest Developer email is ste.sundin@gmail.com; no developer name or business site; Reputation floor applies.
- verified_publisher store verified_publisher=true; discount capped at -1.0 under v3.5 invariant 0c (stale >18mo).
- minimal_permissions manifest Only 'storage' declared; no host permissions, no content scripts, no network surface.
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — no code-quality risk.
- no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.
- install_count store 80,000 installs; +1.0 webstore signal for reach above 10K threshold.
Permissions Breakdown
- storage low Used to persist shortcut configuration; minimal risk, no host access.
Pillar Scores
Permissions0.30
Reputation6.50
Network0.00
Webstore1.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:49
Listing SHA
de2c5ab58a62…
Force block
— not fired
Score recovered
no
Elapsed
18.3s