HTML validator
aofddmgnidinflambjlfkpboeamdldbd
Risk Score
5.15
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Uninstall URL hijack hook present — unusual for a developer tool, raises monetization/tracking concern.
- Install URL hijack opens third-party page on install.
- Privacy policy is Google's generic policy (unscoped, admits 3rd-party sharing) — not extension-specific.
- No developer name; weak accountability for an extension with external host references.
- 21-month staleness with innerHTML DOM sink and no CSP increases future exploit risk.
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; target null but hook fires — webstore signal +3.0.
- install_url_hijack crx onInstalled opens https://htmlvalidator.app/welcome — third-party URL redirect on install.
- generic_privacy_policy store Policy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) → +10.0 privacy.
- no_developer_name store developer_name is empty string — no 'Offered by' accountability signal.
- maintenance_stale store 21 months since last update (12-24mo band) → maintenance pillar +6.0.
- dom_sink_innerhtml crx ace.js uses innerHTML from variable; no CSP present — elevated XSS risk → code quality +2.0.
- no_csp manifest content_security_policy is null; MV3 has strict defaults but csp_present=false noted.
- js_external_hosts crx Extension references example.com, github.com, htmlvalidator.app as external JS hosts.
Permissions Breakdown
- storage low Local extension storage only; no host access granted.
Pillar Scores
Permissions0.30
Reputation6.00
Network0.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:24
Listing SHA
b46a3acee5f3…
Force block
— not fired
Score recovered
no
Elapsed
—