Sticky Notes
oklgdplcbmgephnlmnbcnifhkedgjdbe
Risk Score
3.65
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy; not scoped to this extension at all.
- Developer uses free Gmail address with no verified business identity.
- Content scripts injected on <all_urls> gives page-level access on every site visited.
- tabs permission exposes URLs/titles of all open tabs.
- No CSP declared (MV3 mitigates somewhat, but adds minor code-quality surface).
Evidence
- generic_privacy_policy store Privacy policy links to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_developer store Developer email jacson311@gmail.com; no verified business website or publisher badge.
- content_scripts_all_urls manifest content_scripts_matches includes <all_urls>; runs on every page the user visits.
- verified_publisher store verified_publisher=true; provides partial trust signal but free-webmail floor applies.
- no_cve_findings crx cve_findings_raw is empty; no known vulnerable libraries detected.
- no_code_findings crx code_findings_raw is empty; obfuscation_score=0.0; no exfil or eval patterns.
- low_install_count store Only 946 installs; blast radius limited but still runs on all URLs.
- no_threat_intel_hits api bad_host_hits, affiliate_hits, monetization_hits all empty; single US host.
Permissions Breakdown
- storage low Needed for saving notes locally; standard low-risk permission.
- activeTab low Transient access to current tab on user action; limited scope.
- contextMenus low Adds right-click menu entries; no data access alone.
- notifications low Can display desktop notifications; low direct data risk.
- tabs medium Can read tab URLs and titles across all open tabs.
- content_scripts:<all_urls> medium Script injected on every page; broad reach despite no HIGH permissions.
- host_permissions:https://chrome.google.com/webstore/* low Narrow host permission scoped to Chrome Web Store only.
Pillar Scores
Permissions3.30
Reputation7.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 14:33
Listing SHA
006b3e88a0a9…
Force block
— not fired
Score recovered
no
Elapsed
20.5s