Sticky Notes
maflfnflmcdglonppaeapohmagjnapdl
Risk Score
4.22
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension at all; admits data collection and third-party sharing.
- Developer is anonymous ('B') using free Gmail with no verifiable identity or business presence.
- Extension is 19 months stale with only 500 installs — low accountability if abandoned or sold.
- Description promises download functionality but 'downloads' permission is absent — description mismatch.
- No CSP declared (MV3 default enforced, but adds no custom protection).
Evidence
- generic_privacy_policy store Privacy policy URL is myaccount.google.com — Google's own policy, not scoped to this extension. scope_extension=false, data_collection=true, third_party_sharing=true.
- anonymous_developer store Developer name is single char 'B', email notesforwork941@gmail.com — free webmail, no verifiable identity.
- description_mismatch manifest Description promises 'download' capability but 'downloads' permission not declared.
- maintenance_stale store Last updated November 2024, 19 months since update — falls in 12-24mo band (+6.0).
- no_csp manifest content_security_policy is null; MV3 default applies but no custom CSP hardening.
- low_install_count store Only 500 installs — limited blast radius but also minimal community vetting.
- clean_code_scan crx code_findings_raw empty, obfuscation_score 0.0, no external JS hosts, 1 JS file scanned.
- no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty. No operator siblings.
Permissions Breakdown
- storage low Stores note data locally; minimal risk, expected for a sticky notes app.
Pillar Scores
Permissions0.30
Reputation7.50
Network0.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:53
Listing SHA
8d80de0ccbbf…
Force block
— not fired
Score recovered
no
Elapsed
19.0s