Search It All
ajjjagpncmhojdngglmmpfjiccddcmio
Risk Score
4.48
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL returned HTTP error (fetch_error) — policy unverifiable; scored as missing.
- Bundled jQuery 1.9.1 has 3 moderate CVEs (XSS); version unfixed well below 3.5.0.
- developer_name empty and email prefix 'google.chrome' on non-Google domain is mildly deceptive.
- Extension contacts 6 distinct search engines including ad-supported providers; geo diversity 4 countries.
- new Function() + innerHTML DOM-sink in bundled jQuery amplify XSS risk from CVEs.
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (HTTPError); scored as no policy → Privacy +10.0.
- jquery_1_9_1_cve_triple crx 3 moderate CVEs in bundled jquery@1.9.1; all fixed in >=3.4.0. Not in dev/test path.
- code_function_constructor crx new Function() found in jquery-1.9.1.js; +2.5 code quality.
- dom_sink_innerhtml crx innerHTML assignment in jquery-1.9.1.js; CSP present but CVEs present → +2.0 code quality.
- search_engine_count_6 api threat_intel.search_engine_count=6 contacts bing,ddg,google,startpage,yahoo,yandex.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; Reputation discounted.
- geo_diversity_4_countries api JS hosts span CA/HK/SG/US (count=4); category not VPN/Adblock → Network +1.5.
- developer_name_missing store developer_name is empty string; email prefix mimics Google brand on emailcove.com.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- activeTab low Access only to currently active tab on user gesture; narrow scope.
- storage low Local data persistence; no exfil risk on its own.
- tabs medium Can read URLs and titles of open tabs; moderate privacy surface.
- declarativeContent low Used to show/hide page action based on URL; read-only rule matching.
- contextMenus low Adds right-click menu entries; low standalone risk.
Pillar Scores
Permissions1.30
Reputation3.50
Network2.50
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality4.50
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA
def202d92fa3…
Force block
— not fired
Score recovered
no
Elapsed
29.7s