Web Developer Form Filler
gbagmkohmhcjgbepncmehejaljoclpil
Risk Score
5.48
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — does not scope to this extension's data practices at all.
- Two stale jQuery versions (1.9.1, 1.12.4) bundled with 7 medium-severity XSS CVEs, none patched.
- Content scripts inject into <all_urls> including file:// — broad DOM access on every site the user visits.
- Developer uses free Gmail address with no verifiable business identity; no verified-publisher badge.
- No CSP declared (MV3, but external host www.apache.org referenced); dynamic script creation in bundled jQuery.
Evidence
- generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — +10.0 Privacy.
- cve_moderate_multiple crx 7 CVE entries across jquery@1.9.1 and jquery@1.12.4; >=3 medium CVEs → base +2.0; 4 extra unique IDs → +1.5 extra.
- cve_jquery_no_csp_amplifier crx No CSP + medium CVEs in jQuery (DOM-manipulation lib) → ×1.5 amplifier on CVE pillar.
- broad_host_content_scripts manifest content_scripts_matches includes http://*/* https://*/* file:///*, giving DOM access on all pages.
- free_webmail_developer store developer_email=abzubarev@gmail.com; no verified publisher; no business domain — Reputation +1.5.
- featured_by_google store is_featured_by_google=true applies -2.0 Reputation discount (follows recommended practices).
- no_csp_mv3 manifest content_security_policy=null; MV3 default applies but external host www.apache.org in js_external_hosts.
- maintenance_stale store months_since_update=15; falls in 12-24mo band → +6.0 Maintenance.
CVE Exposures (7)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.12.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.12.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- activeTab medium Grants access to current tab on user action; moderate risk for a form-filler.
- storage low Local data persistence only; standard and low-risk.
- <all_urls> (host_permission) high Content scripts inject into every http/https/file URL — broad DOM access on all sites.
Pillar Scores
Permissions4.50
Reputation6.50
Network4.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality4.50
CVE Exposure5.25
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA
a7fc333e8df1…
Force block
— not fired
Score recovered
no
Elapsed
34.4s