Sinceerly
lhokehflammomchbkmpohfeidffnlpmo
Risk Score
2.77
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Gmail host access allows content script to read full email body text on mail.google.com.
- Free-webmail developer (gmail) with no verified publisher status; low accountability.
- No CSP declared (MV3 default applies but no explicit policy); innerHTML sinks present.
- Privacy policy lacks data retention disclosure; third-party sharing admitted.
- Email content routed through unverified Cloudflare Worker proxy before reaching Anthropic API.
Evidence
- gmail_host_access manifest host_permissions includes https://mail.google.com/* — full Gmail page access.
- free_webmail_developer store Developer email menloparkmidnightoil@gmail.com; no verified publisher badge.
- dom_xss_sink crx Two innerHTML sinks in popup.js and content.js; no CSP to mitigate.
- proxy_endpoint manifest sinceerly-proxy.ben-001.workers.dev is a personal Cloudflare Worker; email data routed through it.
- privacy_retention_missing api Privacy policy fetched: scope_extension=true, data_collection=true, retention=false, third_party_sharing=true.
- stripe_endpoints crx js_external_hosts includes api.stripe.com and buy.stripe.com — payment processing expected for SaaS.
- no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.
- operator_cluster_clean api sibling_count=0; no related extension cluster detected under same fingerprint.
Permissions Breakdown
- activeTab low Grants access to current tab on user action only; scoped and low-risk.
- storage low Local data persistence; no cross-origin exfil risk on its own.
- https://mail.google.com/* medium Host access to Gmail; can read email content in page context.
- https://sinceerly-proxy.ben-001.workers.dev/* low Developer-controlled proxy; access expected for stated AI function.
- https://api.anthropic.com/* low Direct API call to Anthropic; expected for AI email rewriting feature.
Pillar Scores
Permissions2.00
Reputation6.50
Network3.50
Webstore2.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:38
Listing SHA
2ec0fd01d02e…
Force block
— not fired
Score recovered
no
Elapsed
—