WebWise Search
caapepgfdmamgkidjnhijgbiefidebdb
Risk Score
6.53
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Search provider override silently redirects all queries to dev-controlled endpoint with no verified identity.
- Developer domain does not resolve and privacy policy URL is unreachable — effective no-policy state.
- Three bundled jQuery versions (1.9.1, 1.12.4, 3.3.1) carry 4 distinct medium CVEs; no CSP amplifies XSS risk.
- Extension last updated 28 months ago with non-resolving domain — abandoned or preparatory for handoff.
- No developer name, no verified publisher, no install count transparency — minimal accountability signals.
Evidence
- search_provider_override manifest chrome_settings_overrides.search_provider is_default=true pointing to search.web-wise-search.com
- developer_domain_not_resolving api threat_intel: web-wise-search.com resolves=false; privacy policy fetch failed with ConnectionError
- privacy_policy_unreachable api privacy_policy_classification.fetched=false reason=fetch_error:ConnectionError — treated as no policy
- multiple_medium_cves_jquery crx 3 jQuery versions bundled (1.9.1, 1.12.4, 3.3.1); 4 distinct CVE IDs, all medium severity, none at fixed_in version
- no_csp_with_vulnerable_jquery manifest csp_present=false combined with CVE-laden jQuery < 3.5 triggers v2e jquery+no-CSP amplifier
- stale_extension store 28 months since last update; domain non-resolving; abandoned or ownership-transfer risk
- no_developer_name store developer_name empty; no verified publisher badge; no featured badge; unverifiable identity
- dynamic_script_src crx script_src_dynamic in jquery-1.12.4.min.js — remote script injection surface present
CVE Exposures (10)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@1.12.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.12.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- tabs medium Can read tab URLs and titles; medium risk on its own but paired with search override.
- chrome_settings_overrides.search_provider (is_default=true) high Silently replaces default search engine with dev-controlled endpoint; core monetization vector.
Pillar Scores
Permissions4.00
Reputation7.00
Network2.00
Webstore4.00
Maintenance8.50
Privacy10.00
Code Quality3.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 04:37
Listing SHA
75beea9c5606…
Force block
— not fired
Score recovered
no
Elapsed
—