Productivity Owl
eoagmdboiealblmpaahjlhajggndaahi
Risk Score
5.05
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy (snipcss.com) explicitly admits data collection and third-party sharing without scoping to this extension — highest privacy risk tier.
- Three moderate CVEs in bundled jQuery 3.3.1 (XSS); version below fixed_in 3.5.0.
- Content scripts injected on <all_urls> combined with innerHTML DOM sinks and new Function() constructors create real XSS attack surface.
- Developer email is free webmail (gmail) with no verified business domain; privacy policy hosted on unrelated third-party domain.
- Featured badge present but no verified publisher; policy on snipcss.com (unrelated to Productive Mark LLC) undermines accountability.
Evidence
- privacy_policy_scope_mismatch crx Policy at snipcss.com: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar.
- cve_jquery_3.3.1 crx 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) in jquery@3.3.1; fixed in 3.5.0.
- dom_sink_innerhtml_userctrl crx 4 files with innerHTML assignment from variable; CSP present so +0.5 each, but CVEs present → elevated to +2.0 per FIX B.
- function_constructor crx new Function() found in jquery.qtip.js, jquery.qtip.min.js, mustache.js → +2.5 code quality.
- content_scripts_all_urls manifest content_scripts matches <all_urls> with no host_permission restriction; broad page-level access.
- free_webmail_developer store Developer email markrieck81@gmail.com; no business domain; not verified publisher.
- featured_badge store is_featured_by_google=true → -2.0 reputation discount applied.
- js_external_hosts crx 12 distinct external JS hosts including scrapehawk.com, snipcss.com, ionden.com; geo diversity IN+US.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Can read tab URLs/titles; productivity extension monitoring tabs is somewhat expected.
- history medium Access to full browsing history is sensitive; productivity tool may use for tracking.
- storage low Local data persistence only.
- unlimitedStorage low Expands storage quota; low direct privacy risk.
- alarms low Scheduling only, no data access.
- content_scripts:<all_urls> high Injects scripts on every page; broad DOM access combined with innerHTML sinks raises XSS risk.
- host_permissions:fonts.googleapis.com low Narrow font CDN access only.
Pillar Scores
Permissions4.00
Reputation6.00
Network2.50
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality5.50
CVE Exposure3.00
Scoring History
| v3.6 | 5.05 | Medium | review | 2026-06-16 |
| v3.4-rev | 4.34 | Medium | review | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA
a13209971b16…
Force block
— not fired
Score recovered
no
Elapsed
35.1s