Rich Markdown Preview
ojgdkdohicphaegmilnmlgaledfcopca
Risk Score
3.14
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension, yet admits data collection and third-party sharing.
- Developer uses free Gmail address with no verifiable business identity.
- 39 installs means minimal real-world validation of behavior.
- CSP allows unsafe-inline on style-src and external font hosts; minor surface expansion.
- js_external_hosts include chevrotain.io/github.com/react.dev — CSP references but no script-src remote (self-only), low concern.
Evidence
- privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 rule D).
- free_webmail_developer store Developer email masa199311266@gmail.com; no business domain; +1.5 Reputation (free-webmail dev, no business site).
- no_bad_hosts crx threat_intel bad_host_hits, affiliate_hits, monetization_hits all empty — no threat-intel penalties.
- code_findings_clean crx code_findings_raw empty, obfuscation_score 0.0 — Code Quality pillar scores 0.0.
- cve_clean crx cve_findings_raw empty — CVE pillar 0.0.
- single_low_permission manifest Only 'storage' declared; no host_permissions, no content_scripts — minimal capability.
- csp_present_mv3 manifest CSP present with script-src 'self'; MV3 — no network penalty for missing CSP.
- low_installs_no_anomaly store 39 installs; install_perm_anomaly flags all false — no tail-attack-surface penalty.
Permissions Breakdown
- storage low Stores extension settings locally; no data exfil path alone.
Pillar Scores
Permissions0.30
Reputation6.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA
59b8059b0c44…
Force block
— not fired
Score recovered
no
Elapsed
20.9s