Notifier for GitHub
lmjdlojahmbbcodnpecnjnmlddbkjhnn
Risk Score
3.89
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — generic policy admits sharing without scoping to this extension.
- Developer email is free webmail (gmail.com) with no verified business domain; brand_mention flags GitHub impersonation with confirmed_owner=false.
- Uninstall URL hijack flag set (uninstall_url_hijack=true) though target is null — warrants review.
- MV3 but no CSP declared; js_external_hosts include github.com and mozilla.org (content fetched at runtime).
- Extension is featured by Google, partially offsetting reputation concerns, but verified_publisher=false.
Evidence
- privacy_policy_generic_with_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 rule D).
- brand_impersonation_github store brand_mention.is_impersonation=true, confirmed_owner=false, developer on gmail.com; is_featured_by_google=true → +1.0 Reputation.
- free_webmail_developer store sindresorhus@gmail.com; no verified publisher badge; +1.5 Reputation for free-webmail dev without verified business.
- uninstall_url_hijack crx uninstall_url_hijack=true but target=null; rubric +3.0 Webstore not fully applied due to null target, treated as partial signal.
- is_featured_by_google store Featured badge present → -2.0 Reputation discount applied.
- maintenance_6_12mo store months_since_update=12 (boundary 6–12 months) → +3.5 Maintenance.
- no_code_findings_no_cve crx code_findings_raw=[], cve_findings_raw=[], obfuscation_score=0.0; Code Quality=0.0.
- no_csp_mv3 manifest content_security_policy=null on MV3; no v2 penalty (+2.0 Network) since MV3 has strict default; js_external_hosts=[github.com, mozilla.org, developer.mozilla.org].
Permissions Breakdown
- alarms low Used for periodic polling of GitHub notification count; low capability.
- storage low Stores user token/settings locally; standard low-risk permission.
- offscreen low Allows background DOM work without visible tab; low risk given no exfil findings.
Pillar Scores
Permissions0.90
Reputation6.50
Network2.00
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA
e24fbf50fcde…
Force block
— not fired
Score recovered
no
Elapsed
23.7s