Developer Edition Dark
lglfmldlfmbbehalkgiglehhjblbfcjo
Risk Score
4.34
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, but admits data collection and 3rd-party sharing (v3.5-D: +10.0).
- Extension is 33 months stale (last updated Sep 2023), raising abandonment/supply-chain risk.
- Developer email uses mozmail.com alias with no verified business identity.
- No permissions declared — minimal capability, but stale theme with generic policy is a governance gap.
- Install count of 10,000 with triple-stale fingerprint (>24mo) noted but no CVEs mitigate staleness risk.
Evidence
- privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5-D).
- maintenance_stale store Last updated Sep 2023; months_since_update=33 (24-36mo band) → +8.5 maintenance.
- developer_email_alias store Email 10dlhbi46@mozmail.com is a Mozilla relay alias; no verified business domain, identity unverifiable → +1.5 reputation.
- no_permissions manifest permissions[] and host_permissions[] both empty; theme-only extension with zero runtime capability.
- no_csp manifest csp_present=false; MV3 default CSP applies, no custom policy needed for theme, no amplifier penalty triggered.
- no_cve_findings crx cve_findings_raw empty, js_file_count=0, no bundled libraries detected.
- install_count_webstore store 10,000 installs → +1.0 webstore; no siblings, no bad hosts, no affiliate hits.
- operator_cluster_clean api sibling_count=0; no related extensions under same fingerprint.
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore1.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA
9465e09f6c1e…
Force block
— not fired
Score recovered
no
Elapsed
17.9s