JSON Formatter and Viewer
nhkjklblokkpocjeegpnnclbdlaphnfo
Risk Score
4.56
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension stale 26 months — abandoned or unmonitored, prime acquisition/compromise target.
- content_scripts on <all_urls> injects into every page despite JSON-only stated purpose.
- innerHTML DOM-XSS sink with no CSP amplifies code-quality risk on all visited pages.
- new Function() constructor in content.js is a dynamic-execution primitive.
- Developer domain seoweb.ee does not resolve; no accountable entity reachable.
Evidence
- content_scripts_broad manifest content_scripts matches <all_urls> — runs on every page visited, disproportionate for a JSON formatter.
- no_csp manifest content_security_policy is null (MV3 default applies but no explicit hardening declared).
- dom_xss_sink crx innerHTML assigned from variable in client.DYSQn3o3.js with no CSP mitigation.
- function_constructor crx new Function('return this') in content.js — dynamic code execution primitive.
- stale_extension store Last updated April 2024; 26 months since update — maintenance pillar +8.5.
- dev_domain_dead api threat_intel: seoweb.ee does not resolve — developer uncontactable, accountability gap.
- external_js_hosts crx 9 external JS hosts referenced (github.com, reactjs.org, etc.) — no bad-host hits confirmed.
- privacy_policy_third_party_silence store Policy scoped, data_collection true, retention true, but third_party_sharing not addressed (+1.0).
Permissions Breakdown
- storage low Stores user preferences locally; no cross-origin data exposure.
- content_scripts:<all_urls> high Content script injected on every site; broad reach even with no host_permissions declared.
Pillar Scores
Permissions3.30
Reputation5.50
Network2.00
Webstore0.00
Maintenance8.50
Privacy1.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA
ddc954e49389…
Force block
— not fired
Score recovered
no
Elapsed
22.6s