Ethereum Price Ticker
pmdanaagpddigagmcilgcaeedcjhbfpo
Risk Score
6.04
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Abandoned: 40 months since last update with only 73 installs — no active maintenance.
- Privacy policy is Google's generic account policy; does not scope to this extension at all.
- Content script declared on <all_urls> far exceeds stated CoinGecko ticker function.
- Free-webmail developer (gmail) with no verified business identity or publisher badge.
- MV3 with no CSP and content script on all URLs raises residual injection risk.
Evidence
- content_scripts_all_urls manifest content_scripts_matches includes <all_urls> despite extension only needing api.coingecko.com; scope mismatch +1.0 perm.
- stale_extension store Last updated February 2023; 40 months since update — maintenance pillar 10.0.
- generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → privacy pillar 10.0.
- free_webmail_dev store Developer email mrbuffalo92@gmail.com, no business site, no verified publisher → reputation floor 7.5.
- install_url_hijack crx install_url_hijack=true, target is popup.html (internal) — low severity but flag.
- no_csp manifest content_security_policy is null; MV3 has strict default but absence noted for context.
- featured_by_google store is_featured_by_google=true; partial reputation discount applied but free-webmail floor overrides.
- no_cve_no_obfuscation crx cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty — code quality clean.
Permissions Breakdown
- activeTab low Access to currently active tab only; limited scope.
- https://api.coingecko.com/* low Narrow host permission to CoinGecko API; matches stated function.
- notifications low Can show desktop notifications; low abuse potential for a ticker.
- content_scripts <all_urls> high Content script injected on every page despite narrow stated function; scope mismatch.
Pillar Scores
Permissions3.00
Reputation7.50
Network2.00
Webstore4.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA
4ebf453dfdbc…
Force block
— not fired
Score recovered
no
Elapsed
20.4s