CSS Inspector
pjknmkdlmmknhihnkdjijnceokddanem
Risk Score
3.06
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy admits third-party sharing but is not scoped to this extension — data handling opaque.
- Developer uses free webmail (gmail.com) with no verified business identity.
- No CSP declared on MV3 extension; scripting permission adds risk if code is ever injected dynamically.
- Extremely low install count (13) with no ratings makes track record unverifiable.
- Privacy policy fetched but scope_extension=false and third_party_sharing=true triggers max privacy score.
Evidence
- privacy_policy_third_party_sharing api Policy fetched but scope_extension=false and third_party_sharing=true — triggers +10.0 privacy per v3.5 rule D.
- developer_email_free_webmail store Developer email tolumhen@gmail.com is free webmail; no verified business domain. Reputation +1.5.
- no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
- no_code_findings crx code_findings_raw is empty and obfuscation_score=0.0; code quality pillar = 0.0.
- maintenance_recent store Last updated March 2, 2026; months_since_update=3 — within 3-month band, maintenance pillar = 0.0.
- no_host_permissions manifest No host_permissions or content_scripts_matches declared; reach is limited to activeTab on user action.
- no_bad_hosts_or_monetization api threat_intel shows empty bad_host_hits, affiliate_hits, and monetization_hits.
- install_count_very_low store Only 13 installs; no ratings. Blast radius minimal but track record absent.
Permissions Breakdown
- activeTab low Grants access to current tab only on user action; scoped and low-risk for a CSS inspector.
- scripting medium Allows injecting scripts into pages; appropriate for CSS inspection but capable of DOM manipulation.
- clipboardWrite low Write-only clipboard access; consistent with copying CSS values to clipboard.
- tabs medium Can read tab URLs and metadata; broader than activeTab alone but no host permissions compound it.
Pillar Scores
Permissions2.30
Reputation6.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA
8058c9d29dc1…
Force block
— not fired
Score recovered
no
Elapsed
20.5s