Tags for Google Calendar™
ncpjnjohbcgocheijdaafoidjnkpajka
Risk Score
4.35
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — no extension-specific disclosure.
- Brand impersonation: title uses 'Google Calendar™' trademark; brand_mention.is_impersonation=true, developer not confirmed owner.
- Extension is 28 months stale (last updated Feb 2024); no active maintenance signal.
- MV3 with no CSP declared; content script runs on calendar.google.com with no additional sandbox constraint.
- Featured badge partially offsets impersonation risk but developer is unverified third party using a trademarked name.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['google']; confirmed_owner=false; developer is soimon.com.
- generic_privacy_policy store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store Last updated Feb 2024; months_since_update=28; falls in 24-36mo maintenance band (+8.5 raw, capped).
- no_csp manifest content_security_policy=null; MV3 has strict default but no explicit CSP declared.
- featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount but does not override impersonation finding.
- narrow_host_permissions manifest host_permissions scoped only to calendar.google.com; no broad host access, no HIGH-tier permissions.
- clean_code_scan crx code_findings_raw=[]; obfuscation_score=0.0; js_external_hosts=[]; 1 JS file scanned.
- no_bad_hosts_no_monetization api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[]; domain resolves, not throwaway.
Permissions Breakdown
- host_permission: https://calendar.google.com/* medium Content script access to Google Calendar pages; scoped to single service, matches stated function.
- host_permission: http://calendar.google.com/* low HTTP variant of the same calendar host; functionally equivalent, narrow scope.
Pillar Scores
Permissions1.50
Reputation6.50
Network0.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA
771f87325dcd…
Force block
— not fired
Score recovered
no
Elapsed
20.7s