Github Helper
nabepgpnahalibfailklbofhnbilgkmj
Risk Score
5.29
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy (scope_extension=false, admits data_collection+third_party_sharing) — scores max under v3.5 rule D (+10.0).
- Extension is 29 months stale — abandoned with no updates since Jan 2024.
- Brand impersonation: mentions 'github' in name/description, developer is unverified gmail user.
- Free-webmail developer (gmail) with no business domain; free-webmail floor applies to reputation.
- No CSP present (MV3 mitigates somewhat, but scripting permission with no policy is residual risk).
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, brands=['github'], developer_domain=gmail.com, confirmed_owner=false.
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
- maintenance_stale store 29 months since last update → +8.5 maintenance pillar.
- free_webmail_developer manifest Developer email dvirlevydev@gmail.com; no business website; reputation floor >=7.5 applies.
- no_csp manifest content_security_policy=null; MV3 provides default-src restriction but no explicit CSP declared.
- low_install_count store Only 7 installs; micro-audience reduces reach but doesn't eliminate risk from stale/abandoned code.
- code_findings_clean crx code_findings_raw=[], obfuscation_score=0.0, no CVEs; code surface appears benign.
- host_scope_narrow manifest content_scripts scoped to https://*.github.com/*/actions/runs/*; host_permissions limited to github.com.
Permissions Breakdown
- scripting medium Can inject JS into pages; scoped to github.com content_scripts matches, limiting blast radius.
- activeTab low Temporary access to current tab only, requires user gesture.
- https://github.com/ low Single-domain host permission; tightly scoped to GitHub only.
Pillar Scores
Permissions1.30
Reputation7.50
Network2.00
Webstore4.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA
ebe5eaf75251…
Force block
— not fired
Score recovered
no
Elapsed
20.5s