Annotate web pages/CONTEXT
emajnoacacifjgmkkmheackniabamonm
Risk Score
3.34
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- content_scripts on <all_urls> with no CSP: JS injected into every page with no sandbox constraint.
- jquery@3.2.0 carries 3 medium XSS CVEs (fix available at 3.5.0); ×1.5 amplifier applies (no CSP + DOM-manipulation lib).
- Privacy policy is Google's generic account policy, not scoped to this extension; scores as non-scoped with data collection + 3rd-party sharing admitted.
- Developer uses free Gmail address with no verifiable business identity.
- innerHTML sink in content_script.js without CSP guard amplifies XSS risk from bundled vulnerable jQuery.
Evidence
- content_scripts_matches=<all_urls> manifest Extension injects into every URL visited; high reach.
- jquery@3.2.0 with 3 medium CVEs crx CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; all fixed in 3.5.0.
- dom_sink_innerhtml_userctrl + no CSP crx innerHTML in content_script.js with csp_present=false triggers FIX B +2.0.
- privacy_policy_generic store Google account policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
- free_webmail_developer store Developer email neuralnetworks2.0@gmail.com; no business domain; +1.5 reputation.
- no_csp manifest content_security_policy is null on MV3; amplifies CVE risk.
- rating=3.5 store Below-average rating; rating_count not disclosed.
- months_since_update=8 store 3-6 month band → maintenance +1.5.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.0 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Can read tab URLs and metadata; moderate info exposure.
- activeTab low Scoped to current tab on user action; limited reach.
- storage low Local storage for annotations; no remote exfil implied.
- webNavigation medium Observes navigation events across all tabs; broad passive visibility.
- unlimitedStorage low Allows large local storage; no direct privacy risk.
- content_scripts:<all_urls> high Injects JS into every page visited; high reach capability.
Pillar Scores
Permissions3.30
Reputation6.50
Network0.00
Webstore0.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure5.25
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA
b43da7922a1a…
Force block
— not fired
Score recovered
no
Elapsed
53.0s