Web paint
ejllkedmklophclpgonojjkaliafeilj
Risk Score
4.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Google generic privacy policy used — not scoped to this extension, admits data collection and 3rd-party sharing (D rule: +10.0 privacy).
- Content scripts injected on <all_urls> with innerHTML DOM-XSS sinks in both index.js and options.js; no CSP to mitigate.
- Free-webmail developer (outlook.com) with no developer name; identity unverifiable despite verified-publisher badge.
- Broad host_permissions *://*/*ombined with content scripts gives full page read/write capability on every site.
- React 16.13.1 bundled; older React versions have known XSS-adjacent issues, no CSP protection present.
Evidence
- privacy_policy_generic store Policy is Google's own account privacy policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
- dom_xss_sink_no_csp crx innerHTML sinks in index.js and options.js; csp_present=false triggers +2.0 code quality per FIX B rule.
- broad_host_permissions manifest host_permissions *://*/* + content_scripts <all_urls>; HIGH capability on all sites.
- free_webmail_no_dev_name store developer_email=paintonweb@outlook.com, developer_name empty; verified_publisher caps reputation floor at 2.0.
- verified_publisher_featured store Both verified_publisher and is_featured_by_google true; applied reputation discounts but floored at 2.0.
- react_16_no_csp crx React 16.13.1 bundled; no CSP. v2 calibration: react<16.4 amplifier not triggered (16.13.1 > 16.4) but innerHTML risk noted.
- maintenance_3_6mo store months_since_update=8; falls in 6-12 month band → +3.5 maintenance.
- js_external_hosts crx External JS host references: fb.me, mui.com, reactjs.org — documentation/CDN URLs, no bad-host hits.
Permissions Breakdown
- tabs medium Can read tab URLs and titles across all tabs.
- storage low Local data persistence; limited standalone risk.
- activeTab low Access limited to user-activated tab; low risk.
- *://*/* high Broad host access to all URLs; enables content injection on any site.
- content_scripts:<all_urls> high JS injected into every page; combined with innerHTML sinks raises XSS risk.
Pillar Scores
Permissions4.50
Reputation2.00
Network0.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:50
Listing SHA
7b8bd231468e…
Force block
— not fired
Score recovered
no
Elapsed
—