Local Code Text Editor
mjgcajafbmnmniihkdgdhcijnpempjlm
Risk Score
3.66
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — scores maximum privacy risk.
- Developer uses free Gmail address with no verified business identity, elevating reputation risk.
- install_url_hijack and uninstall_url_hijack flags set — extension redirects on install/uninstall.
- new Function() constructor in Monaco editor loader may execute dynamic code without CSP guard.
- Privacy policy hosted on unrelated domain (pdfwork.com), suggesting a generic/boilerplate policy.
Evidence
- privacy_policy_generic_admits_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — worst-case privacy score of 10.0 per v3.5 rule D.
- free_webmail_developer store Developer email oliross739@gmail.com is free webmail with no business website, no verified publisher badge.
- install_url_hijack crx install_url_hijack=true targeting editor.html; uninstall_url_hijack=true with null target — both flags raised.
- function_constructor_monaco crx new Function() in Monaco editor loader and worker files; no CSP present — dynamic code execution risk.
- dom_sink_innerhtml_no_csp crx innerHTML from variable in editor JS; csp_present=false elevates this from +0.5 to +2.0 per FIX B.
- no_csp_mv3 manifest MV3 extension with no content_security_policy declared; no v2 network penalty but code risks amplified.
- operator_cluster_no_siblings api sibling_count=0; no operator-cluster amplification.
- cve_findings_empty crx No CVEs detected in bundled libraries; CVE pillar = 0.0.
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:56
Listing SHA
ba86e6f9c99f…
Force block
— not fired
Score recovered
no
Elapsed
23.6s