Easy Color Picker
bgahcehknhgmjoggmkibghafppcfoaci
Risk Score
5.32
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but does not scope to this extension and admits third-party sharing — scores maximum privacy risk.
- Bundled jquery@1.12.4 has 4 medium-severity XSS CVEs; no CSP present amplifies exploitability.
- Broad host permissions (https://*/*, http://*/*) paired with scripting allow JS injection on every site visited.
- Developer is free-webmail Gmail account with no business name, reducing accountability.
- No CSP with vulnerable DOM-manipulation library (jQuery) increases XSS attack surface on injected content.
Evidence
- broad_host_permissions manifest https://*/* and http://*/* grant script injection access to all websites via scripting permission.
- jquery_cve_cluster crx jquery@1.12.4 bundles 4 medium-severity XSS CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023).
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP hardens against CVE-affected jQuery.
- privacy_policy_inadequate api Policy fetched (101964 chars) but scope_extension=false, data_collection=false, third_party_sharing=true — generic, not scoped.
- free_webmail_dev_no_name store developer_email=webtools.any@gmail.com; developer_name empty; no verified business identity.
- install_url_hijack crx install_url_hijack=true, target=/debug-tab.html — opens internal debug page on install.
- google_analytics_hit crx monetization_hits includes www.google-analytics.com; telemetry present.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true provide some trust offset, but do not override privacy/CVE risks.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.12.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.12.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- activeTab medium Access to current tab content on user action; low standalone risk but combined with scripting increases surface.
- storage low Local data persistence only; no cross-origin risk.
- scripting high Allows dynamic JS injection into pages; paired with broad host permissions is a high-impact capability.
- https://*/* high Broad host access across all HTTPS sites enables scripting injection everywhere.
- http://*/* high Broad host access across all HTTP sites, extends injection surface to insecure pages.
Pillar Scores
Permissions5.50
Reputation6.00
Network3.50
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality3.50
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA
1aae6a4afd7e…
Force block
— not fired
Score recovered
no
Elapsed
28.2s