Window Weather
mbfiddfdjipgbncnamfciamfcpbkmdji
Risk Score
5.16
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; collects and shares data with third parties.
- Extension last updated April 2022 (50 months ago) — effectively abandoned.
- No CSP declared; DOM-XSS innerHTML sink present in bundled JS with no mitigating policy.
- Geolocation permission collects precise user location with no adequate disclosure.
- Small install base (17) with stale codebase increases tail-attack-surface supply-chain risk.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
- maintenance_stale store 50 months since last update (>36mo) → Maintenance pillar 10.0.
- dom_sink_innerhtml crx code_findings_raw reports dom_sink_innerhtml_userctrl in main JS; no CSP present → Code Quality +2.0.
- no_csp crx content_security_policy is null; MV3 has strict default but no explicit CSP declared.
- geolocation_permission manifest Geolocation declared; matches weather function but collects PII with inadequate privacy disclosure.
- external_host_reactjs_org crx js_external_hosts includes reactjs.org (React docs CDN reference, not a live data endpoint). Low risk.
- operator_cluster_csp_siblings api sibling_count=0 on compound/email dims; csp_host_set siblings=16 but no compound match — not penalized.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
Permissions Breakdown
- geolocation medium Accesses physical location; reasonable for a weather app but is PII.
Pillar Scores
Permissions1.50
Reputation5.00
Network0.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
3f49c67d0ce6…
Force block
— not fired
Score recovered
no
Elapsed
21.7s