Crypto Price Alerts for Binance - Coinocular
ehmhocjlcagmfeokjhmgmednhbdhpgep
Risk Score
5.76
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Binance brand impersonation by unverified gmail developer — no confirmed ownership.
- Privacy policy is Google's generic policy (not scoped to this extension); admits data collection & 3rd-party sharing.
- Uninstall URL hijack redirects to developer's webflow page; install URL hijack also present.
- jQuery 3.3.1 bundles 3 moderate XSS CVEs (unfixed); no CSP present amplifying DOM-sink risk.
- 8 external JS hosts contacted including api.telegram.org and www.mexc.com — broad network reach for a price-alert tool.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; developer is gmail user, not Binance.
- generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- install_uninstall_url_hijack crx install_url_hijack=true; uninstall_url_hijack redirects to binance-crypto-price-alerts.webflow.io/feedback.
- cve_jquery_3.3.1 crx 3 moderate CVEs in bundled jquery@3.3.1 (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
- no_csp crx content_security_policy is null; MV3 default applies but DOM-sink XSS risk from jQuery CVEs is elevated.
- broad_external_hosts crx 8 JS external hosts: api.telegram.org, www.mexc.com, www.tradingview.com, webflow.io, binance, cryptopricealerts.net.
- free_webmail_developer store Developer email kaleemovick@gmail.com; no verified publisher; no business domain.
- geo_diversity api JS hosts span 4 countries (CA, IN, NL, US); category is not VPN/Translation/Adblock.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Stores local alert config; minimal risk.
- offscreen low Used for background audio/DOM tasks; low risk in isolation.
- notifications low Required for price alert notifications; fits stated function.
- alarms low Periodic polling for price checks; fits stated function.
- https://www.binance.com/en/trade/pro/* medium Host access scoped to Binance pro trade page; moderate – can read trading page content.
Pillar Scores
Permissions1.50
Reputation8.00
Network4.50
Webstore8.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:30
Listing SHA
a25a7d1d8ebe…
Force block
— not fired
Score recovered
no
Elapsed
27.5s