Keyboard Shortcuts
lplcmnhgijkkmflbmhabnccgelffpnog
Risk Score
3.89
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy (scope_extension=false, admits data collection and 3rd-party sharing) — worst-case privacy score.
- Developer uses free-webmail (gmail.com) with no verified business identity.
- Extension not updated in 26 months — stale but low-capability.
- Featured by Google partially offsets reputation risk but developer remains unverified individual.
- No permissions or host access declared; actual capability is minimal.
Evidence
- no_permissions manifest permissions[] and host_permissions[] are both empty; extension has minimal capability.
- generic_google_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email joepestro@gmail.com; no business domain; domain_age_ct not queried.
- featured_by_google store is_featured_by_google=true provides partial reputation credit.
- stale_extension store Last updated April 4 2024; 26 months since update — maintenance score elevated.
- clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty, 2 JS files scanned.
- no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty; operator sibling_count=0.
- mv3_no_csp manifest MV3 extension; no CSP declared — MV3 has strict defaults so no network penalty applied.
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA
4e241ab5a566…
Force block
— not fired
Score recovered
no
Elapsed
16.6s