Pomodoro
nanjaegameeoomamnliimipmmfabdngd
Risk Score
3.87
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy URL returned SSL error — policy could not be evaluated; treated as unfetched.
- Developer uses free Gmail address with no verified business identity.
- Extension is 14 months stale (6-12 mo band); maintenance risk elevated.
- No CSP declared (MV3 default applies but no explicit policy); innerHTML sink present.
- No developer name listed; accountability gap.
Evidence
- privacy_policy_fetch_failed api Privacy policy URL SSL error — fetched==false; scored as +10.0 privacy pillar.
- free_webmail_developer store dev email d1nhnh4n@gmail.com; no developer name; no verified business domain.
- verified_publisher store is_featured_by_google==true; verified_publisher==true; reputation discount applied.
- dom_sink_innerhtml crx innerHTML sink found in assets/index.html-ceefcec5.js; no CSP; DOM-XSS risk.
- months_since_update_14 store Last updated April 2025; 14 months since update → maintenance +6.0.
- no_bad_hosts_no_cves api threat_intel bad_host_hits empty; cve_findings_raw empty; CVE pillar 0.0.
- low_permissions manifest Only alarms, notifications, storage, offscreen, system.display — all LOW tier.
- no_host_permissions manifest host_permissions empty; content_scripts_matches empty; no broad web access.
Permissions Breakdown
- alarms low Schedules timer callbacks; core to Pomodoro function.
- notifications low Shows timer alerts; expected for productivity timer.
- storage low Persists user settings locally.
- offscreen low Allows background audio/DOM; reasonable for timer sounds.
- system.display low Read-only display info; likely for notification positioning.
Pillar Scores
Permissions1.20
Reputation5.50
Network0.00
Webstore0.00
Maintenance6.00
Privacy10.00
Code Quality0.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA
3de5d23cc5c9…
Force block
— not fired
Score recovered
no
Elapsed
21.0s