LookGood Live
mleflnbfifngdmiknggikhfmjjmioofi
Risk Score
3.27
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy, not scoped to this extension; data_collection and third_party_sharing are true.
- Broad host_permissions (http://*/*, https://*/*) + content_scripts on <all_urls> allow full page read/write on every site.
- Developer name is blank; no 'Offered by' name visible despite verified-publisher badge.
- External JS hosts include vuejs.org and webcameffects.app — two non-CDN origins loaded by the extension.
- Small install base (5,000) with broad host access increases tail-attack-surface concern.
Evidence
- broad_host_permissions manifest host_permissions include http://*/* and https://*/* plus content_scripts on <all_urls>.
- generic_privacy_policy store Privacy URL points to myaccount.google.com/privacypolicy — Google's own policy, not extension-scoped.
- verified_publisher_featured store Extension carries both verified_publisher and is_featured_by_google badges.
- no_developer_name store developer_name is empty string; no visible 'Offered by' attribution.
- external_js_hosts crx JS contacts accounts.google.com, fonts.gstatic.com, vuejs.org, webcameffects.app.
- no_code_findings crx code_findings_raw empty; obfuscation_score 0.0; 5 files scanned cleanly.
- recently_updated store months_since_update=3; maintenance score 0.
- no_cve_findings crx cve_findings_raw empty; vue 3.4.13 bundled with no known CVEs flagged.
Permissions Breakdown
- storage low Persists extension settings locally; no user data exfil on its own.
- http://*/* high Broad host access to all HTTP sites; enables content-script injection everywhere.
- https://*/* high Broad host access to all HTTPS sites; same risk surface as http broad access.
- content_scripts <all_urls> high Content scripts run on every page; combined with broad host = full page read/write.
Pillar Scores
Permissions4.50
Reputation2.00
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 16:35
Listing SHA
711fa2d8ef48…
Force block
— not fired
Score recovered
no
Elapsed
—