Simple Word Counter
npbdkdphbeljebmbcddcpignamfbfpkg
Risk Score
3.49
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Content script on <all_urls> can read page content across every site visited.
- Privacy policy is Google's generic account policy — not scoped to this extension at all.
- Developer identity is minimal ('tb') with no verified publisher badge.
- Rating 3.6 may indicate quality/trust concerns though install base is small.
- Privacy policy admits data collection and third-party sharing without extension-specific scope.
Evidence
- content_scripts_all_urls manifest content_scripts_matches includes <all_urls> — JS runs on every page the user visits.
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_identity_weak store Developer name 'tb', email tb@tarotmancer.com; no verified publisher badge.
- featured_by_google store is_featured_by_google=true provides modest trust signal.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — clean code surface.
- no_cve_findings crx cve_findings_raw empty; no vulnerable bundled libraries detected.
- recently_updated store months_since_update=3; maintenance risk negligible.
- threat_intel_clean api No bad_host_hits, affiliate_hits, or monetization_hits; developer domain resolves and not throwaway.
Permissions Breakdown
- storage low Stores local preferences; no cross-origin data access.
- content_scripts:<all_urls> high Content script injected on every page; can read page content across all sites.
Pillar Scores
Permissions4.00
Reputation5.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA
02b42f3edb2e…
Force block
— not fired
Score recovered
no
Elapsed
17.1s