Dictionariez: Your Dictionary, Your Language
diojcfpekhhnndfmggknljpnfpcccbhc
Risk Score
4.43
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- angular@1.8.3 has 1 high + 5 moderate + 3 low CVEs; no fixed version available — library cannot be safely patched.
- No CSP combined with angular DOM-manipulation lib and high CVEs triggers ×1.5 CVE amplifier (CVE pillar=7.5).
- eval_user_input (angular.$eval) and script_src_dynamic in multiple bundles enable code execution from external input.
- Privacy policy admits third-party data sharing but lacks retention disclosure; developer is free-webmail with no dev name.
- Content scripts injected on <all_urls> with no CSP means XSS escalation surface is every page the user visits.
Evidence
- angular@1.8.3 CVEs crx 9 CVEs total: CVE-2024-21490 (high), CVE-2023-26116/17/18, CVE-2022-25844/25869, CVE-2025-0716, CVE-2024-8372/73; fixed_in=null.
- No CSP + angular DOM lib → CVE ×1.5 amplifier manifest content_security_policy is null and angular is a DOM-manipulation lib with high/medium CVEs; amplifier applied.
- eval_user_input crx dictheader.bundle.js and options.bundle.js call angular.$eval() on variables — direct eval of user-controlled input.
- script_src_dynamic crx examples.bundle.js dynamically creates <script> elements at runtime — remote code loading vector.
- free-webmail developer, no dev name store developer_email=revir.qing@gmail.com, developer_name empty; verified_publisher=true, is_featured=true.
- privacy policy: third_party_sharing=true, retention=false api Policy scoped to extension and acknowledges data collection + 3rd-party sharing but no retention clause.
- 12 external JS hosts, 3 countries crx Contacts cn.bing.com, wiktionary.org, collinsdictionary.com, oxfordlearnersdictionaries.com etc.; country_count=3.
- content_scripts <all_urls> + no CSP manifest Scripts run on every URL; absence of CSP removes last-line-of-defence against XSS escalation via CVE-laden angular.
CVE Exposures (9)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2023-26117 | angular@1.8.3 | moderate | — | angular vulnerable to regular expression denial of service via the $resource ser |
| CVE-2023-26116 | angular@1.8.3 | moderate | — | angular vulnerable to regular expression denial of service via the angular.copy( |
| CVE-2024-21490 | angular@1.8.3 | high | — | angular vulnerable to super-linear runtime due to backtracking |
| CVE-2025-0716 | angular@1.8.3 | low | — | AngularJS improperly sanitizes SVG elements |
| CVE-2022-25844 | angular@1.8.3 | moderate | — | angular vulnerable to regular expression denial of service (ReDoS) |
| CVE-2024-8372 | angular@1.8.3 | low | — | AngularJS allows attackers to bypass common image source restrictions |
| CVE-2024-8373 | angular@1.8.3 | low | — | AngularJS allows attackers to bypass common image source restrictions |
| CVE-2022-25869 | angular@1.8.3 | moderate | — | Angular (deprecated package) Cross-site Scripting |
| CVE-2023-26118 | angular@1.8.3 | moderate | — | angular vulnerable to regular expression denial of service via the <input type=" |
Permissions Breakdown
- activeTab low Scoped to user-activated tab only; limited blast radius.
- tabs medium Can read tab URLs and metadata across open tabs.
- storage low Local data persistence; low standalone risk.
- contextMenus low UI integration only; no data access.
- offscreen low Allows off-screen document; moderate capability but no host access.
- content_scripts:<all_urls> high Scripts injected into every page; broad reach combined with tabs elevates risk.
Pillar Scores
Permissions3.30
Reputation4.50
Network4.50
Webstore1.00
Maintenance0.00
Privacy2.00
Code Quality7.50
CVE Exposure7.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:28
Listing SHA
6cb2cf8f78d0…
Force block
— not fired
Score recovered
no
Elapsed
43.8s