Simple Todo List
mepehlihjoiibmoompngpijhnhlfndai
Risk Score
4.15
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Nearly 3 years since last update (35 months) — abandoned extension, no security patches expected.
- Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and third-party sharing.
- Developer uses free Gmail account with no verified business identity.
- Extension references external documentation hosts (github.com, MDN, etc.) — minor supply-chain note.
- Very low install count (87) limits blast radius but also means no community vetting.
Evidence
- maintenance_stale store Last updated July 28, 2023 — 35 months ago, approaching zombie threshold.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_free_webmail store Developer email 27aksoy27@gmail.com — free webmail, no business domain, no verified publisher badge.
- no_permissions manifest Zero declared permissions and zero host_permissions — very low capability surface.
- csp_present_mv3 manifest CSP: script-src 'self'; object-src 'self' — strict, no remote script loading.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, no eval/fetch/exfil signals detected.
- external_hosts_doconly crx js_external_hosts: MDN, Google Developers, Flutter docs, Emscripten, GitHub — documentation only.
- no_cve_findings crx cve_findings_raw empty; no vulnerable bundled libraries detected.
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore0.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
7eee4c3cd56d…
Force block
— not fired
Score recovered
no
Elapsed
16.7s