Camera Picture In Picture (PIP Overlay)
pgejmpeimhjncennkkddmdknpgfblbcl
Risk Score
2.86
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension at all; admits data collection and 3rd-party sharing (v3.5 Rule D: +10.0).
- No developer name listed in store; identity accountability is weak.
- Manifest uses i18n placeholders for name/description, reducing store-level transparency.
- Maintenance score elevated: 6 months since last update (borderline stale).
- Verified publisher discount capped at -1.0 under v3.5 Rule E due to generic/non-scoped privacy policy admitting 3rd-party sharing.
Evidence
- generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — Rule D applies: +10.0 privacy.
- verified_publisher store Verified publisher badge present; discount capped at -1.0 per v3.5 Rule E (monetization/scope issue).
- no_permissions manifest permissions[], host_permissions[], content_scripts_matches[] all empty — minimal capability surface.
- no_external_js_hosts crx js_external_hosts empty; no outbound network surface observable.
- no_code_findings crx code_findings_raw empty, obfuscation_score=0.0 — clean static scan.
- no_developer_name store developer_name is empty string; reduces identity accountability.
- domain_age api webcameffects.app first cert 2023-11-16, age 1034 days, cert_count=133 — not new, resolves.
- maintenance store 6 months since last update — borderline stale band (+1.5).
Pillar Scores
Permissions0.00
Reputation3.50
Network0.00
Webstore2.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-15 11:57
Listing SHA
b542ad9d1acb…
Force block
— not fired
Score recovered
no
Elapsed
—