WProofreader: AI grammar check & rewrite tool
ehlmgkidbfjedfdanfechlikaolobpgh
Risk Score
5.39
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetch failed (HTTP error); cannot verify data handling for AI grammar tool processing all page text.
- broad host permissions (http://*/*, https://*/*) + cookies + scripting enables reading page content and cookies on every site.
- new Function() constructor in bundled JS (wscbundle.js) — dynamic code execution risk.
- innerHTML assignment from variable (dom_sink_innerhtml_userctrl) with no CSP — potential DOM-XSS vector.
- No developer name listed; uninstall URL hijack flag set with null target adds uncertainty.
Evidence
- broad_host_permissions manifest http://*/* and https://*/* grant read/script access to every site visited.
- cookies_high_perm manifest cookies permission paired with <all_urls> host access — ×1.2 amplifier applied.
- no_csp crx content_security_policy is null; no CSP mitigates DOM-XSS findings.
- function_constructor crx wscbundle.js: new Function() constructor used — dynamic code execution.
- dom_sink_innerhtml_userctrl crx wscbundle.js: innerHTML assigned from variable with no CSP — +2.0 FIX B applies.
- privacy_policy_fetch_failed api fetched==false (HTTPError); policy cannot be assessed — scored +10.0.
- install_url_hijack store install_url_hijack=true with null target; minor concern without confirmed 3rd-party URL.
- uninstall_url_hijack store uninstall_url_hijack=true with null target; cannot confirm 3rd-party redirect.
Permissions Breakdown
- activeTab low Grants access to current tab on user action only.
- tabs medium Can read tab URLs and metadata across browser.
- storage low Local key-value storage; limited scope.
- unlimitedStorage low Allows large local data; minor risk alone.
- cookies high Can read/write cookies; paired with <all_urls> host access amplifies risk.
- scripting high Programmatic script injection into pages; broad with <all_urls>.
- http://*/* high Broad host access to all HTTP sites.
- https://*/* high Broad host access to all HTTPS sites including banking/health.
Pillar Scores
Permissions7.00
Reputation5.00
Network4.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
8794431e7785…
Force block
— not fired
Score recovered
no
Elapsed
26.9s