WhenX: Mark Linkedin Profiles with notes
dgafcidlgmbcehokgdeghmfnbpbfhihh
Risk Score
5.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but admits third-party data sharing with no extension-specific scope — privacy pillar maxed at 10.
- Four medium-severity CVEs in bundled jquery@2.1.4 (XSS); library is well below fixed version 3.5.0.
- Brand impersonation flag: 'linkedin' mentioned but developer is not a confirmed owner/partner.
- Sandbox CSP includes unsafe-eval and unsafe-inline on script-src; extension injects scripts into all Google TLDs and LinkedIn.
- history permission gives full browser history access beyond stated LinkedIn-notes function; scope mismatch signal.
Evidence
- privacy_policy_no_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case classification under v3.5 rule D.
- cve_jquery_xss crx jquery@2.1.4 carries CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251 (all moderate); fixed_in 3.5.0.
- brand_impersonation store brand_mention.is_impersonation=true for 'linkedin'; confirmed_owner=false; developer is not LinkedIn.
- sandbox_csp_unsafe_eval_inline manifest Sandbox CSP: script-src 'self' 'unsafe-inline' 'unsafe-eval'; elevates XSS risk from CVE-laden jQuery.
- history_permission manifest history permission declared; broader than needed for a LinkedIn profile annotation tool.
- connect_src_mixpanel manifest connect-src includes api.mixpanel.com — third-party analytics/telemetry endpoint.
- content_scripts_all_google_tlds manifest Content scripts injected on all ~200 Google TLDs plus LinkedIn; broad beyond stated LinkedIn function.
- function_constructor crx new Function() constructor found in scripts/background.js — dynamic code execution risk.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.1.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.1.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.1.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.1.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- tabs medium Can read tab URLs and titles across all open tabs.
- history medium Can read full browser history — sensitive user data.
- activeTab low Scoped to user-activated tab only.
- contextMenus low Adds right-click menu items, low capability.
- storage low Local/sync extension storage only.
- scripting medium Can inject JS into pages matching host_permissions.
- offscreen low Off-screen DOM processing; limited direct risk.
- *://*.google.com/* high Broad host permission covering all Google domains + content scripts injected.
- https://*.linkedin.com/* high Full read/write access to LinkedIn; core function but high-value data surface.
Pillar Scores
Permissions5.50
Reputation4.00
Network5.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 06:00
Listing SHA
3e2fb713b0df…
Force block
— not fired
Score recovered
no
Elapsed
28.9s