ImageAssistant Batch Image Downloader
dbjbempljhcmhlfpfacalomonjpalpko
Risk Score
5.71
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 (arbitrary code execution); not patched.
- High CVE-2026-27601 + 2 medium jQuery XSS CVEs; no CSP amplifies DOM-XSS risk.
- webRequest + declarativeNetRequestWithHostAccess + <all_urls> gives full request interception on every site.
- Developer uses free Gmail with no verified business identity; no developer name listed.
- Privacy policy admits third-party data sharing but lacks retention disclosure; stale >18mo.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (ACE, critical); fixed in 1.12.1 — not updated.
- high_cve_underscore crx underscore@1.8.3 has CVE-2026-27601 (high DoS via recursion); fixed in 1.13.8.
- medium_cves_jquery crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (XSS); fixed in 3.5.0.
- no_csp_amplifier manifest No content_security_policy; DOM-XSS sink (innerHTML) in bootstrap + jQuery CVEs = amplified risk.
- high_perm_all_urls_webrequest manifest webRequest + declarativeNetRequestWithHostAccess + <all_urls> + scripting = full request/content control.
- free_webmail_no_dev_name store Dev email netactspcl@gmail.com; no developer name; free webmail with no verified business domain.
- privacy_third_party_sharing api Privacy policy: scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- stale_20mo store Last updated Oct 2024, 20 months stale; CVEs present; verified publisher cap applies (0c).
CVE Exposures (8)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2017-20165 | debug@unknown | high | 3.1.0 | debug Inefficient Regular Expression Complexity vulnerability |
| CVE-2017-16137 | debug@unknown | low | 2.6.9 | Regular Expression Denial of Service in debug |
| querystringify@unknown | querystringify@unknown | high | 2.0.0 | Prototype Pollution in querystringify |
| CVE-2022-0686 | url-parse@unknown | critical | 1.5.8 | Authorization Bypass Through User-Controlled Key in url-parse |
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- tabs medium Access to tab URLs/titles; needed for image discovery across pages.
- scripting medium Inject scripts into pages; broad capability paired with <all_urls>.
- webNavigation medium Observe navigation events; used to detect image-bearing pages.
- webRequest high Intercept/observe all network requests; high capability.
- declarativeNetRequest medium Block/redirect requests declaratively; moderate risk.
- declarativeNetRequestWithHostAccess high Modify requests on all hosts; elevates declarativeNetRequest to high.
- storage low Local settings persistence; low risk.
- downloads medium Trigger file downloads; core to stated function.
- notifications low Show desktop notifications; low risk.
- contextMenus low Right-click menu entries; low risk.
- fontSettings low Read/write browser font settings; low risk, unusual for a downloader.
- <all_urls> (host) high Full cross-origin access; combined with webRequest/scripting raises capability significantly.
Pillar Scores
Permissions5.50
Reputation7.50
Network4.00
Webstore3.00
Maintenance6.00
Privacy2.00
Code Quality2.00
CVE Exposure9.00
Scoring History
| fsssiedxx'sssiedx | 6.24 | High | review | 2026-07-28 |
| v3.6 | 5.71 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA
6f1e1a2e5df6…
Force block
— not fired
Score recovered
no
Elapsed
31.2s