NG Corretor Ortográfico (Português)
pbpnngfnagmdlicfgjkpgfnnnoihngml
Risk Score
6.21
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Broad host permissions (all HTTP/HTTPS) + scripting allow full page content read/modify on every site visited.
- Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
- Developer is anonymous with a Gmail address; no verifiable business identity.
- Extension is 25 months stale (last updated May 2024) with no CSP, raising supply-chain takeover risk.
- Featured badge partially offsets reputation risk but cannot compensate for anonymous dev + unscoped policy.
Evidence
- broad_host_permissions manifest host_permissions include http://* and https://* paired with scripting — full DOM access on every site.
- anonymous_gmail_developer store Developer listed as 'Anonymous' with email portugaldev@gmail.com; no business domain.
- generic_privacy_policy api Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store Last updated May 2024; months_since_update=25, exceeding 24-month threshold.
- no_csp manifest content_security_policy is null; MV3 has strict default but no explicit CSP declared.
- featured_badge store is_featured_by_google=true; partially mitigates reputation risk but does not resolve policy gap.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0; no malicious patterns detected in 7 JS files.
- external_host_mozilla crx js_external_hosts includes mozilla.org only — consistent with spellcheck library usage.
Permissions Breakdown
- scripting high Can inject arbitrary JS into all pages via broad host permissions.
- storage low Local extension data storage; minimal risk alone.
- tabs medium Access to tab URLs and metadata across all open tabs.
- http://*/* high Broad host access to all HTTP sites; pairs with scripting for full page access.
- https://*/* high Broad host access to all HTTPS sites; pairs with scripting for full page access.
Pillar Scores
Permissions6.50
Reputation7.50
Network2.00
Webstore1.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:03
Listing SHA
9bf1755a338c…
Force block
— not fired
Score recovered
no
Elapsed
19.9s