SendMe Telegram
ckkfnchnfmgpiejgaacmbngkcjbaaipd
Risk Score
5.21
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Telegram brand impersonation by unverified gmail developer; confirmed by brand_mention.is_impersonation.
- Privacy policy is generic Google account policy — does not scope to this extension, admits data collection and 3rd-party sharing.
- Content scripts run on all HTTP/HTTPS pages (broad reach) combined with install/uninstall URL hijack signals.
- jQuery 2.1.4 bundled with 4 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251), none fixed.
- Developer uses free Gmail address with no verified business domain; uninstall URL hijack flag set.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; developer domain is gmail.com, not Telegram.
- generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — +10.0 privacy.
- content_scripts_broad manifest content_scripts_matches: http://*/* and https://*/* — injects into every page visited.
- cve_jquery_moderate_x4 crx jquery@2.1.4 has 4 moderate XSS CVEs; all unfixed (fixed_in >= 3.4.0, bundled 2.1.4).
- uninstall_url_hijack crx uninstall_url_hijack=true; extension sets custom uninstall URL to unknown 3rd-party destination.
- install_url_hijack crx install_url_hijack=true; onInstalled opens external URL.
- free_webmail_developer store Developer email tonkado@gmail.com; no verified publisher badge; no business domain.
- telemetry_google_analytics crx Google Analytics in monetization_hits; only telemetry-tier, no bad hosts detected.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.1.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.1.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.1.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.1.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- activeTab low Access only to currently active tab on user gesture; limited surface.
- tabs medium Can read tab URLs and titles across all open tabs.
- contextMenus low Adds right-click menu items; low standalone risk.
- storage low Local extension data storage only.
- content_scripts http://*/* https://*/* high Broad content-script injection on all URLs; wide reach even without explicit host_permissions.
Pillar Scores
Permissions4.00
Reputation7.50
Network3.50
Webstore7.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA
a7939e9ba91d…
Force block
— not fired
Score recovered
no
Elapsed
27.4s