Markdown Reader
medapdbncneneejhbgcjceippjlfkmkg
Risk Score
1.88
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Developer email on 163.com (free Chinese webmail) with no dev name listed; identity unverifiable.
- Content scripts match broad wildcard file-extension patterns across all HTTP/file origins.
- Privacy policy discloses third-party data sharing; actual scope to this extension confirmed.
- Uninstall URL hijack flag set (target null); minor concern but worth noting.
- No developer name provided; reduced accountability.
Evidence
- verified_publisher + featured store Extension carries both verified_publisher and is_featured_by_google badges; strong trust signal.
- developer_email_domain store Developer email benjavan@163.com on free Chinese webmail; no business domain; looks_throwaway=true.
- content_scripts_scope manifest Content scripts scoped to markdown/txt/md file extensions on *://*/ and file://; not all_urls.
- privacy_policy_classification api Policy fetched; scope_extension=true, data_collection=true, retention=true, third_party_sharing=true.
- no_bad_hosts_no_cves crx No bad host hits, no CVEs, no affiliate/monetization hits, obfuscation_score=0, code_findings empty.
- uninstall_url_hijack crx uninstall_url_hijack=true but target is null; may be benign feedback page.
- js_external_hosts crx CSP script-src is 'self' only; external hosts developer.mozilla.org and vuejs.org in HTML links only.
- maintenance store Last updated June 2026; months_since_update=0; actively maintained.
Permissions Breakdown
- storage low Stores user preferences locally; no exfil risk.
- tabs medium Can read tab URLs/titles; moderate privacy surface.
- content_scripts (*://*/*.md etc.) medium Injects into markdown/text file URLs across all hosts; scoped to file-type pattern, not all_urls.
Pillar Scores
Permissions2.30
Reputation3.50
Network0.00
Webstore2.50
Maintenance0.00
Privacy1.00
Code Quality0.00
CVE Exposure0.00
Scoring History
| sssiednecaa3818dp727562726963xsx | 2.07 | Low | allow | 2026-09-07 |
| <fsssiedxa'sssiedx | 1.88 | Low | allow | 2026-08-13 |
| <fsssiedxa | 1.75 | Low | allow | 2026-08-13 |
| <fsssiedxa$"sssiedx | 2.44 | Low | allow | 2026-08-13 |
| xx pfsssiedxasssiedx | 1.61 | Low | allow | 2026-08-08 |
| "fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 1.93 | Low | allow | 2026-08-08 |
| %22fsssiedxa$"sssiedx | 2.09 | Low | allow | 2026-08-08 |
| %27fsssiedxa$"sssiedx | 1.70 | Low | allow | 2026-08-08 |
| 'fsssiedxa$'sssiedx | 2.25 | Low | allow | 2026-08-08 |
| 1.99 | Low | allow | 2026-08-08 | |
| fsssiedxa<sssiedx | 1.74 | Low | allow | 2026-08-08 |
| fsssiedxa sssiedx | 1.54 | Low | allow | 2026-07-28 |
| fsssiedxa"sssiedx | 1.37 | Low | allow | 2026-07-28 |
| fsssiedxa'sssiedx | 1.45 | Low | allow | 2026-07-28 |
| fsssiedxa$'sssiedx | 1.61 | Low | allow | 2026-07-28 |
| sssieddrubricxsx | 1.67 | Low | allow | 2026-07-28 |
| v3.6 | 1.88 | Low | allow | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
9bb1ce9a9f9c…
Force block
— not fired
Score recovered
no
Elapsed
19.7s