Simple Color Picker
oekcgbklihkajpddgklkakahiabhcjhm
Risk Score
4.01
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension is 39 months stale (>36mo) with 10K installs — prime acquisition/hijack target.
- Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and third-party sharing.
- No CSP declared (MV3 default strict, but content_security_policy field is null).
- Featured badge provides some trust signal but developer is unverified publisher.
- No permissions declared — minimal capability risk, but stale + bad privacy policy remains a concern.
Evidence
- maintenance_stale store Last updated March 2023; 39 months since update triggers max maintenance score (+10.0) plus zombie booster (+1.0 >36mo+10K installs), capped at 10.
- privacy_generic_google_policy store Privacy URL is myaccount.google.com/privacypolicy — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 per v3.5 rule D.
- featured_by_google store is_featured_by_google=true provides -2.0 reputation discount (Follows recommended practices badge).
- no_permissions manifest permissions[], host_permissions[], content_scripts_matches[] all empty — zero capability risk.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — clean code surface.
- no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty; developer domain ezhil.dev resolves and not throwaway.
- operator_cluster_clean api sibling_count=0; no clustered sibling extensions under same fingerprint.
- no_cve_findings crx cve_findings_raw empty; no bundled vulnerable JS libraries detected.
Pillar Scores
Permissions0.00
Reputation3.00
Network0.00
Webstore1.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA
c77671f1febf…
Force block
— not fired
Score recovered
no
Elapsed
21.2s