Neon Pool Table
lpcnmhphplmplfhhimehmpbfhclpkgge
Risk Score
5.44
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Severely abandoned: last updated November 2017, 106 months ago — MV2 zombie with no observed maintenance.
- No developer identity: no name, no email — zero accountability if compromised.
- Privacy policy is Google's generic account policy — does not scope to this extension at all.
- MV2 with no CSP declared — adds +2.0 network penalty per v2 calibration.
- Zero JS files scanned and empty manifest — extension surface area is completely unverifiable.
Evidence
- extreme_staleness store Last updated November 2017; 106 months since update — maintenance score 10.0.
- no_developer_identity store developer_name and developer_email both empty — no accountability or contact.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — scores 10.0.
- mv2_no_csp manifest Manifest V2 with csp_present=false — +2.0 network penalty applied per v2 calibration fix (b).
- zero_js_files crx js_file_count=0, js_files_scanned=0, code_findings_raw empty — content unverifiable.
- no_permissions manifest permissions[], host_permissions[], content_scripts_matches[] all empty — permissions pillar 0.0.
- low_install_count store Only 630 installs; no install-threshold boosts apply.
- no_verified_publisher store verified_publisher=false, is_featured_by_google=false — reputation starts at 5.0 with +2.5 for no dev name/email.
Pillar Scores
Permissions0.00
Reputation7.50
Network2.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 04:35
Listing SHA
953b5540ce99…
Force block
— not fired
Score recovered
no
Elapsed
—