CSS Stacking Context inspector
apjeljpachdcjkgnamgppgfkmddadcki
Risk Score
5.35
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — does not scope to this extension at all (scope_extension=false, admits data collection and 3rd-party sharing).
- Two eval_user_input findings via chrome.devtools.inspectedWindow.eval() with no CSP; code execution risk.
- innerHTML DOM-XSS sink with no CSP present amplifies risk.
- Broad host permissions (http://*/* + https://*/*) with content_scripts on <all_urls>; stale 22 months.
- Extension last updated 22 months ago; triple-stale fingerprint concern (>18mo, MV3 but no CSP).
Evidence
- privacy_policy_generic store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- eval_user_input_x2 crx Two files use chrome.devtools.inspectedWindow.eval(variable); +2.5 code quality per eval_user_input signal.
- dom_sink_innerhtml_no_csp crx innerHTML sink with csp_present=false triggers FIX B amplifier → +2.0 code quality.
- no_csp_mv3 manifest MV3 extension but content_security_policy is null; v2 fix (b) +2.0 network.
- broad_host_permissions manifest http://*/* and https://*/* granted; content_scripts on <all_urls>. DeveloperTools discount applied (-1.5).
- maintenance_stale store 22 months since update → maintenance score 6.0 (12-24mo band).
- featured_by_google store is_featured_by_google=true → -2.0 reputation discount applied.
- tail_attack_surface api install_perm_anomaly.tail_attack_surface=true → +1.0 webstore.
Permissions Breakdown
- storage low Stores extension settings locally; low impact.
- scripting medium Allows programmatic script injection into pages; medium risk.
- http://*/* high Broad host access to all HTTP sites; high reach.
- https://*/* high Broad host access to all HTTPS sites; high reach.
- <all_urls> (content_scripts) high Content scripts injected on every URL; broad surface.
Pillar Scores
Permissions5.50
Reputation4.00
Network2.00
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA
1f66acb70540…
Force block
— not fired
Score recovered
no
Elapsed
28.5s