Java Assist
niofihbhibghmpojpckcdbekjfeddkdb
Risk Score
4.27
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension not updated in 33 months — zombie-level staleness, high acquisition/hijack risk.
- Privacy policy is Google's generic account policy (scope_extension=false, admits data collection and 3rd-party sharing) — rates +10.0 under v3.5 rule D.
- Developer email is free Gmail with no verified business domain — unaccountable identity.
- 10K installs on a near-abandoned extension is a valuable takeover target.
- No permissions declared but 1 JS file contacts docs.oracle.com — minimal but opaque surface.
Evidence
- stale_extension store Last updated December 2023; 33 months since update — exceeds 24-month zombie threshold.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email clapper.fdc@gmail.com; domain_age_ct not queried (free webmail). No verified publisher badge.
- no_permissions manifest permissions[], host_permissions[], content_scripts_matches[] all empty; minimal declared capability.
- external_js_host crx js_external_hosts: [docs.oracle.com] — single external host, no bad-host hits.
- no_cve_findings crx cve_findings_raw empty; no bundled vulnerable libraries detected.
- no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 1 JS file scanned.
- install_count_10k store 10,000 installs on a stale, low-accountability extension increases takeover-value risk.
Pillar Scores
Permissions0.00
Reputation6.50
Network0.00
Webstore1.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-11 07:38
Listing SHA
7a136767990f…
Force block
— not fired
Score recovered
no
Elapsed
—