Quick Find for Google Chrome™
dejblhmebonldngnmeidliaifgiagcjj
Risk Score
4.52
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Brand impersonation: title includes 'Google Chrome™' trademark; developer is unaffiliated gmail user.
- Privacy policy is Google's generic account policy — not scoped to this extension; data_collection and third_party_sharing both true.
- Bundled jquery@2.1.1 carries 4 medium CVEs (XSS); not updated to fixed version 3.5.0+.
- Content scripts inject into all HTTP/HTTPS/FTP pages with no host restriction — full DOM access on every site visited.
- Developer email is free webmail (gmail.com); no verified publisher badge; update date unknown.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['google']; developer_email=pdotjs@gmail.com; confirmed_owner=false.
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false; data_collection=true; third_party_sharing=true.
- cve_jquery_2.1.1 crx jquery@2.1.1 has 4 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); fixed in 3.5.0.
- broad_content_scripts manifest content_scripts_matches covers ftp://*/* http://*/* https://*/* — DOM access on all sites.
- free_webmail_developer store developer_email=pdotjs@gmail.com; no business domain; not verified publisher.
- maintenance_unknown store last_updated is empty string; months_since_update=null; cannot confirm active maintenance.
- ga_telemetry crx monetization_hits: www.google-analytics.com (telemetry); js_external_hosts also includes github.com, stackoverflow.com.
- featured_by_google store is_featured_by_google=true; partially mitigates reputation risk but does not override brand-impersonation or privacy gaps.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.1.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.1.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- content_scripts: ftp://*/* http://*/* https://*/* high Broad content script injection across all HTTP/HTTPS/FTP pages; reads and manipulates any page DOM.
Pillar Scores
Permissions2.00
Reputation7.50
Network2.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA
47caa9115af7…
Force block
— not fired
Score recovered
no
Elapsed
24.6s