Chrome JavaScript Editor
adfelndhcceedaphfhehpblofeohjmdb
Risk Score
5.37
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension at all; admits data collection and 3rd-party sharing.
- Extension has not been updated in 40 months (zombie); abandoned code increases compromise risk.
- DOM-XSS sink (innerHTML) in editor.js with no CSP, elevating exploitability of any XSS.
- Developer uses free Gmail address with no business domain or verified-publisher badge.
- External JS hosts (beautifier.io, codemirror.net, jsdelivr.com) loaded without CSP integrity controls.
Evidence
- maintenance_stale store Last updated Feb 2023; 40 months since update — zombie tier (+10.0 maintenance).
- privacy_generic_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
- no_csp manifest content_security_policy is null; MV3 default is strict but external hosts are referenced without integrity hashes.
- dom_xss_sink crx editor.js: innerHTML written from variable with no CSP; DOM-XSS risk elevated per FIX B.
- reputation_gmail_dev store Developer email niawkung@gmail.com; free webmail, no verified publisher, no business domain.
- external_js_hosts crx 3 external JS hosts: beautifier.io, codemirror.net, www.jsdelivr.com — supply-chain risk without SRI/CSP.
- featured_by_google store is_featured_by_google=true; partial trust signal, but does not offset staleness or privacy issues.
- cve_findings crx cve_findings_raw empty; no CVE exposure detected.
Permissions Breakdown
- tabs medium Can read tab URLs and metadata; moderate risk for a dev tool.
- contextMenus low Adds right-click menu entries; minimal risk.
- offscreen low Creates offscreen document; low risk without host permissions.
- storage low Local key-value storage; no cross-origin exfil vector alone.
Pillar Scores
Permissions1.90
Reputation6.50
Network2.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA
68718e2f555f…
Force block
— not fired
Score recovered
no
Elapsed
21.6s