Weava Highlighter - PDF & Web
cbnaodkpfinfiipjblikofhlhlcickei
Risk Score
5.79
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Broad host_permissions (http://*/* + https://*/*) with scripting + webRequest on 200K installs — high-value compromise target.
- Privacy policy fetched but scope_extension==false AND admits data collection + third-party sharing — scores maximum privacy risk.
- 28 months without update (>24mo band) raises abandonment/supply-chain risk; no changelog visible.
- function_constructor and innerHTML DOM-sink in contentPage.js/polyfills.js outside of bundled PDF.js library.
- No developer name listed and unverified publisher despite significant install base.
Evidence
- broad_host_permissions manifest http://*/* and https://*/* grant access to all web content; paired with scripting and webRequest.
- privacy_policy_generic api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 (v3.5-D).
- stale_extension store Last updated Feb 2024; 28 months since update — 24-36mo band (+8.5 maintenance).
- code_function_constructor crx new Function() found in contentPage.js and multiple PDF.js assets; +2.5 from function_constructor signal.
- dom_xss_sink crx innerHTML assignment in polyfills.js; CSP present so +0.5 applied, not elevated.
- no_developer_name store developer_name is empty string; +1.0 reputation penalty.
- featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied.
- no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.
Permissions Breakdown
- contextMenus low Adds right-click menu items; minimal risk.
- declarativeNetRequest medium Can modify/block network requests; medium risk without host access alone.
- scripting high Paired with broad host_permissions; can inject JS into any page.
- storage low Local data persistence; low risk on its own.
- tabs medium Can read tab URLs and titles across all tabs.
- unlimitedStorage low Allows large local storage; no direct data-exfil risk.
- webNavigation medium Observes navigation events across all URLs; privacy surface.
- webRequest high Can observe all HTTP requests across all URLs given broad host_permissions.
- notifications low Shows desktop notifications; low standalone risk.
- host_permissions: http://*/* + https://*/* high Broad host access across all websites; amplifies scripting and webRequest.
Pillar Scores
Permissions6.50
Reputation5.50
Network2.00
Webstore3.00
Maintenance8.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA
b09b4bc62e2f…
Force block
— not fired
Score recovered
no
Elapsed
32.1s