cemhbhdbggdannbdmajoldjnnnlhaghf
cemhbhdbggdannbdmajoldjnnnlhaghf
Risk Score
5.10
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Default search engine overridden to StartXXL without clear developer accountability or verified identity.
- Privacy policy is Google's generic account policy — not scoped to this extension at all.
- jquery@3.1.0 bundles 3 medium-severity CVEs (XSS); fixed version is 3.5.0.
- No developer name, email, or publisher verification; anonymous extension.
- Install-time URL hijack opens third-party page on install.
Evidence
- search_provider_override manifest chrome_settings_overrides sets StartXXL as default search engine (is_default=true).
- install_url_hijack manifest install_url_hijack=true; extension opens a third-party URL on installation.
- no_developer_identity store developer_name, developer_email, and title are all empty; no verified publisher.
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- jquery_cve crx jquery@3.1.0 has CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all medium); fixed in 3.5.0.
- no_csp manifest content_security_policy is empty; csp_present=false with MV3 (no explicit CSP set).
- months_since_update_unknown store last_updated missing; maintenance pillar scored 0 (no data).
- external_js_host crx js_external_hosts: [www.startxxl.com]; 1 external host, country_count=1 (DE).
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.1.0 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.1.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.1.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- host_permissions: *://*.startxxl.com/* low Scoped to a single domain matching the search provider; limited reach.
- chrome_settings_overrides.search_provider (is_default=true) medium Silently replaces default search engine with StartXXL; user-facing and hard to reverse.
Pillar Scores
Permissions5.00
Reputation7.50
Network2.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:33
Listing SHA
da0efd06a13e…
Force block
— not fired
Score recovered
no
Elapsed
—