Text Editor
demheclfdlemkkpadenmajhjbdhbjjml
Risk Score
3.52
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- jquery@1.11.1 bundled with 3 medium CVEs (XSS); fixed version is 3.5.0 — library severely out of date.
- script_src_dynamic in jQuery enables dynamic script injection; no CSP to mitigate.
- Multiple innerHTML DOM-XSS sinks in CodeMirror dialog and searchbox with no CSP guard.
- Developer uses free-webmail Gmail address with no verified publisher badge; accountability limited.
- Privacy policy lacks retention disclosure and is silent on third-party sharing.
Evidence
- jquery_vulnerable crx jquery@1.11.1 bundled; 3 medium CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fix requires upgrade to >=3.5.0.
- script_src_dynamic crx Dynamic <script> creation in jquery-1.11.1.min.js; no CSP present on MV3 extension to block remote script loads.
- dom_sink_innerhtml_userctrl crx Two innerHTML sinks (dialog.js, searchbox.js); csp_present=false and CVEs present → elevated DOM-XSS risk.
- free_webmail_dev store Developer email sevina.lucia@gmail.com; no verified publisher badge; reputation pillar elevated.
- featured_by_google store is_featured_by_google=true; partial reputation credit applied.
- privacy_policy_retention_missing api Policy fetched; scope_extension=true; data_collection=false; but retention=false and third_party_silence=true.
- no_csp manifest content_security_policy=null on MV3; v2 +2.0 Network rule not triggered (MV3 exempt), but amplifies CVE/DOM risk.
- js_external_hosts crx 12 external JS hosts detected (codemirror.net, github.com, etc.); >3 distinct domains → Network +1.5.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.11.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.11.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.11.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Saves extension settings/data locally; no cross-site or data-exfil risk.
Pillar Scores
Permissions0.30
Reputation6.50
Network2.00
Webstore1.00
Maintenance1.50
Privacy2.00
Code Quality6.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA
e5b708f0366e…
Force block
— not fired
Score recovered
no
Elapsed
30.0s