PageMo - Sticky notes & Memo in any page
pofjbbchhigcnknnkohmonholngahbgk
Risk Score
6.34
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Extension abandoned 42 months ago — no security patches for critical DOM/script sinks.
- Content scripts inject into ALL http/https pages with no CSP; dynamic script creation + innerHTML sinks amplify XSS risk.
- Privacy policy is Google's own account policy — not scoped to this extension at all; data practices undisclosed.
- Free-webmail developer (gmail) with no business domain; no verified publisher status.
- function_constructor (new Function) in bundled app JS with no CSP guard raises code-execution risk.
Evidence
- abandoned_extension store Last updated December 2022 — 42 months ago; no security maintenance expected.
- no_csp crx content_security_policy is null; no CSP mitigations for DOM/script sinks.
- broad_content_scripts manifest content_scripts_matches covers http://*/* and https://*/* — all pages.
- dynamic_script_creation crx script_src_dynamic in options/js/app.cd3b0707.js; can load remote code without CSP guard.
- generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, not scoped to this extension.
- free_webmail_dev store Developer email crosstime.sun@gmail.com; no business domain or verified publisher badge.
- js_external_hosts crx Extension contacts: goo.gl, ramilaliyev.com, summernote.org, www.buymeacoffee.com, www.google.com (5 hosts).
- low_rating store Rating 3.2 with 435 installs; no review red flags detected but below-average user satisfaction.
Permissions Breakdown
- storage low Used to persist sticky notes locally; expected for this category.
- activeTab low Transient tab access on user action; limited scope.
- contextMenus low Adds right-click menu items; low standalone risk.
- webNavigation medium Observes navigation events across browsing; broader than needed for note app.
- content_scripts http://*/* https://*/* high Injects JS into every page visited; broad reach combined with innerHTML/dynamic script sinks.
Pillar Scores
Permissions3.30
Reputation7.00
Network4.00
Webstore2.50
Maintenance10.00
Privacy10.00
Code Quality6.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:06
Listing SHA
62b6c8a11322…
Force block
— not fired
Score recovered
no
Elapsed
28.6s