StackOverflow Code Snippet Copier
mcgnogkmgagddkecfcfakidaamdchkja
Risk Score
5.78
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- Extension abandoned: 37 months since last update (>36mo maintenance score 10.0).
- Brand impersonation: 'StackOverflow' in name, developer is unverified gmail user with no confirmed ownership.
- Free-webmail developer (gmail) with no business website raises identity accountability concerns.
- No CSP declared (MV3 has strict default, but adds +2.0 Network for MV2 check — MV3 so +2.0 not applied; still no policy transparency).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; developer is gmail user 'vaibhav.jain197@gmail.com'.
- privacy_policy_generic store Policy is Google account policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 D).
- maintenance_abandoned store months_since_update=37 (>36mo) → Maintenance pillar 10.0.
- free_webmail_developer store Developer email is gmail.com; no business domain; developer name only 'VJ'.
- is_featured_by_google store is_featured_by_google=true; provides partial reputation mitigation but stale update reduces discount.
- no_cve_no_bad_hosts crx cve_findings_raw empty, bad_host_hits empty, affiliate_hits empty, monetization_hits empty.
- code_clean crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty, 3 JS files scanned.
- narrow_host_scope manifest content_scripts scoped only to https://stackoverflow.com/*; no broad host permissions.
Permissions Breakdown
- clipboardWrite medium Allows writing to clipboard; expected for a copy-button tool, low abuse potential alone.
- content_scripts: https://stackoverflow.com/* low Narrowly scoped to stackoverflow.com only; matches stated function.
Pillar Scores
Permissions1.00
Reputation7.50
Network2.00
Webstore3.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
e4bf7604133f…
Force block
— not fired
Score recovered
no
Elapsed
20.7s