Password Alert
noondiphcddnnabmjcihcjfbhfklnnep
Risk Score
3.78
Risk Level:
Low
Recommendation:
✅ ALLOW
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing (+10.0 privacy pillar).
- <all_urls> host permission + scripting injects into every page; high-capability surface even from a trusted developer.
- Months since update is 15 — falls in 12-24mo stale band (+6.0 maintenance); security tool staleness is operationally risky.
- CSP connect-src allows https://* (broad outbound); acceptable for security tool but noteworthy.
- Developer is Google (recognized org) and is_featured_by_google=true, substantially mitigating reputation risk.
Evidence
- recognized_org_developer store Developer email passwordalert-feedback@google.com; domain google.com resolves, not throwaway.
- is_featured_by_google store Extension marked is_featured_by_google=true; follows recommended practices badge applied.
- generic_privacy_policy api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
- broad_host_permission manifest <all_urls> in host_permissions + content_scripts_matches; scripting permission paired — high capability.
- maintenance_stale store Last updated March 2025; 15 months ago → 12-24mo band = +6.0 maintenance score.
- csp_connect_broad manifest CSP connect-src https://* allows outbound to any HTTPS host; +2.5 network, offset by security category discount.
- no_bad_hosts_no_cves crx cve_findings_raw empty, bad_host_hits empty, code_findings_raw empty, obfuscation_score=0.0.
- capability_gate_check manifest Recognized-org -2.0 discount capped at -1.0 per v2 rule 0b: extension has broad host+scripting (HIGH-impact capability).
Permissions Breakdown
- identity low OAuth identity access; low risk alone, needed for Google account detection.
- identity.email medium Reads signed-in user email; core to password-alert function but sensitive PII.
- notifications low Displays alerts; no data exfil risk.
- scripting medium Can inject scripts into pages; paired with <all_urls> increases surface.
- storage low Local config/hash storage; expected for password-hash caching.
- tabs medium Can read tab URLs; needed for phishing-page detection.
- <all_urls> (host_permission) high Content script on every URL; required for phishing detection but broad surface.
Pillar Scores
Permissions4.10
Reputation2.00
Network2.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA
ec84d52ad8d6…
Force block
— not fired
Score recovered
no
Elapsed
24.8s