Bitcoin Price Ticker
bgddejjmhilkdllbakkgddjodommlimc
Risk Score
2.95
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- jQuery 3.3.1 bundles 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) — no CSP amplifies XSS risk.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Developer is a free-webmail address (gmail) with no business name — limited accountability.
- Content script injected into blockchain.com (financial site) — innerHTML sinks in same codebase heighten DOM-XSS impact.
- No CSP declared (MV3) — innerHTML sinks in jQuery and popup scripts lack mitigating policy.
Evidence
- gmail_developer_no_name store Developer email ivana.frolova1403@gmail.com; no business name listed — free-webmail identity.
- generic_privacy_policy store Privacy URL points to myaccount.google.com/privacypolicy — not scoped to this extension; admits data collection + 3rd-party sharing.
- cve_moderate_jquery crx jquery@3.3.1 carries CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all moderate); fixed in 3.4-3.5.
- no_csp_dom_sinks crx No content_security_policy + 3 innerHTML sinks across jquery and popup scripts; CVE v2 amplifier applies.
- content_script_financial_site manifest content_scripts_matches includes https://*.blockchain.com/* — script runs on financial platform pages.
- verified_and_featured store verified_publisher=true and is_featured_by_google=true — partial trust signal, but publisher is gmail identity.
- no_bad_hosts_no_affiliates crx threat_intel shows no bad_host_hits, no affiliate_hits, no monetization_hits — clean network signals.
- recently_updated store Last updated April 2026 (2 months ago) — maintenance risk minimal.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Stores extension state locally; no data exfil risk on its own.
- background low Keeps alarms/polling alive; standard for a price ticker.
- alarms low Schedules periodic price fetches; low risk.
- http://api.coindesk.com/ (host) low Narrow API endpoint for BTC price data; fits stated function.
- https://api.coindesk.com/ (host) low Narrow API endpoint for BTC price data; fits stated function.
- https://blockchain.com/* (host) medium Content script injected into blockchain.com — reads page content on financial site.
- https://*.blockchain.com/* (host) medium Wildcard subdomain content script on financial platform; elevated but scoped.
Pillar Scores
Permissions1.30
Reputation6.50
Network0.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA
b1d5eb144239…
Force block
— not fired
Score recovered
no
Elapsed
30.9s