JSON Formatter
ondecobpcidaehknoegeapmclapnkgcl
Risk Score
3.52
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Content script runs on <all_urls> — reads/modifies every page the user visits despite only needing JSON pages.
- Privacy policy is Google's generic account policy: does not scope to this extension, admits data collection and third-party sharing.
- Developer is a free-webmail (gmail) account with no verified business identity or developer name.
- No CSP declared on MV3 extension that loads external host jsonlint.com — network surface uncontrolled.
- Verified-publisher badge present, but policy mismatch and gmail identity limit its assurance value.
Evidence
- content_scripts_matches=<all_urls> manifest Script injected on every URL; overbroad for a JSON formatter that only needs to act on JSON responses.
- privacy_policy_generic store Policy URL is myaccount.google.com — Google's own account policy. scope_extension=false, data_collection=true, third_party_sharing=true.
- developer_identity_weak store developer_email=todd.garland@gmail.com, developer_name empty, no business domain. Free-webmail identity.
- js_external_hosts crx Extension references jsonlint.com as external JS host; no CSP to constrain this surface.
- verified_publisher=true store Chrome Web Store verified publisher badge present — partial trust signal.
- cve_findings_raw=[] crx No CVEs detected in bundled libraries.
- code_findings_raw=[] crx No eval, obfuscation, exfil, or dynamic-script findings detected. obfuscation_score=0.0.
- months_since_update=5 store Last updated January 7, 2026 — within 3-6 month band, low staleness penalty.
Permissions Breakdown
- activeTab medium Grants access to current tab's content on user action; moderate risk, scope-limited.
- content_scripts <all_urls> high Content script injected on every URL gives broad page-read/write capability across all sites.
Pillar Scores
Permissions2.30
Reputation6.50
Network0.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA
06fd12965b2d…
Force block
— not fired
Score recovered
no
Elapsed
19.8s