Google Keep Chrome Extension
lpcaedmchfhocbbapmcbpinfpgnhiddi
Risk Score
2.90
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Broad host permissions (http://*/, https://*/) paired with scripting enable page content access on all sites.
- Privacy policy is Google's generic corporate policy; not scoped to this extension's data practices.
- Generic privacy policy admits data collection and third-party sharing without extension-specific scope.
- Developer name field is empty in listing despite Google ownership; minor governance gap.
- file://*/* host permission extends access to local filesystem content.
Evidence
- broad_host_permissions manifest host_permissions include http://*/ and https://*/ granting content access on all websites.
- recognized_organization store Developer email keep-extension-support@google.com; google.com resolves, not throwaway, confirmed owner.
- featured_by_google store is_featured_by_google == true; extension follows recommended practices per store badge.
- privacy_policy_generic api policies.google.com/privacy: fetched, scope_extension=false, data_collection=true, third_party_sharing=true. D rule applies → +10.
- no_code_findings crx code_findings_raw empty; obfuscation_score 0.0; no exfil or eval indicators detected.
- no_cve_findings crx cve_findings_raw empty; no vulnerable bundled libraries detected.
- clean_threat_intel api bad_host_hits, affiliate_hits, monetization_hits all empty; no operator siblings.
- mv3_strict_csp manifest MV3 with script-src 'self'; no unsafe-eval/inline; no MV2 CSP penalty applies.
Permissions Breakdown
- activeTab low Scoped to current tab on user action only; limited blast radius.
- identity medium OAuth token access; needed to authenticate Google account for Keep.
- identity.email medium Reads user email address via identity API; scoped to Google sign-in.
- contextMenus low Adds right-click menu items; low standalone risk.
- tabs medium Can read tab URLs/titles; justified for saving page content to Keep.
- unlimitedStorage low Allows large local storage; no data exfil risk on its own.
- scripting medium Can inject scripts into pages; broad when paired with host_permissions.
- file://*/* medium Host permission covering local files; unusual for a notes tool.
- http://*/ high Broad HTTP host access enabling content injection on all HTTP sites.
- https://*/ high Broad HTTPS host access enabling content injection on all HTTPS sites.
Pillar Scores
Permissions3.80
Reputation2.00
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiedna6d59a7cdp727562726963xsx | 3.45 | Low | review | 2026-09-15 |
| fsssiedxn31926fb6zafdsaxax><!--></ScRiPt>asddn31926fb6zsssiedx | 3.15 | Low | review | 2026-09-06 |
| sssiednf20ff077dp727562726963xsx | 3.22 | Low | review | 2026-09-06 |
| v3.69203"();}]9063 | 3.61 | Low | allow | 2026-08-05 |
| v3.6"onmouseover=rDzt(92182)" | 3.08 | Low | allow | 2026-08-05 |
| dfb{{98991*97996}}xca | 3.27 | Low | review | 2026-08-05 |
| v3.6&n905893=v934763 | 3.14 | Low | allow | 2026-08-05 |
| <fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx | 3.38 | Low | review | 2026-07-30 |
| <fsssiedx{"sssiedx | 3.19 | Low | review | 2026-07-30 |
| <fsssiedx{ | 3.16 | Low | allow | 2026-07-30 |
| <fsssiedx{$"sssiedx | 3.08 | Low | allow | 2026-07-30 |
| fsssiedx<sssiedx | 3.28 | Low | review | 2026-07-30 |
| fsssiedxd'sssiedx | 3.12 | Low | allow | 2026-07-30 |
| fsssiedxd$'sssiedx | 3.11 | Low | allow | 2026-07-30 |
| sssieddrubricxsx | 3.10 | Low | allow | 2026-07-30 |
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%4E%6D%44%70%28%39%30%39%39%34%29%22 | 3.12 | Low | allow | 2026-07-29 |
| v3.6" MY9E=NmDp([!+!]) IZP=" | 3.28 | Low | allow | 2026-07-29 |
| dfb__${98991*97996}__::.x | 3.14 | Low | allow | 2026-07-29 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 3.10 | Low | review | 2026-07-29 |
| <th:t="${dfb}#foreach | 3.04 | Low | review | 2026-07-29 |
| '"()&%<zzz><ScRiPt >NmDp(9550)</ScRiPt> | 3.09 | Low | review | 2026-07-29 |
| v3.6&n967865=v950991 | 3.19 | Low | allow | 2026-07-29 |
| v3.6 | 2.90 | Low | allow | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA
41979e7a0658…
Force block
— not fired
Score recovered
no
Elapsed
23.7s