Color Picker by AdCreative.ai
bijgpkifioecdiebmfdlecnbgiommlmf
Risk Score
5.75
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- jquery@1.11.1 bundles 3 medium CVEs (XSS); no CSP amplifies exploitability on <all_urls> content script.
- Privacy policy does not scope to this extension and admits data collection + third-party sharing (score 10.0).
- Extension stale 26 months with vulnerable jquery; no update despite public CVE disclosures.
- Content script runs on <all_urls> with no CSP, expanding attack surface for bundled XSS vulnerabilities.
- Dynamic <script> injection in jquery.js combined with absent CSP enables potential remote code loading paths.
Evidence
- vulnerable_jquery crx jquery@1.11.1 bundled; 3 medium CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in 3.5.0.
- no_csp crx content_security_policy is null; MV3 default applies but no explicit restriction on script sources.
- content_script_all_urls manifest content_scripts_matches: [<all_urls>] — DOM access on every site visited.
- privacy_policy_not_scoped store Policy fetched but scope_extension==false; admits data_collection and third_party_sharing without extension scope.
- stale_extension store Last updated April 2024; 26 months since update with known CVEs unfixed.
- dynamic_script_creation crx script_src_dynamic signal in js/jquery.js; JSONP transport creates dynamic script elements.
- no_developer_name store developer_name is empty string; identity relies solely on email tufan@adcreative.ai.
- featured_by_google store is_featured_by_google==true; partial trust signal, but does not offset CVE/privacy gaps.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.11.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.11.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.11.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Used to persist color picker settings/history locally.
- content_scripts:<all_urls> high Content script injected on all URLs enables DOM access across every site the user visits.
Pillar Scores
Permissions3.30
Reputation5.00
Network3.00
Webstore3.00
Maintenance8.50
Privacy10.00
Code Quality5.50
CVE Exposure5.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA
2fdc5acc730e…
Force block
— not fired
Score recovered
no
Elapsed
25.7s