股票提醒助手
goiffchdhlcehhgdpdbocefkohlhmlom
Risk Score
6.44
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Abandoned 38 months — zombie extension with broad *://*/ host access; prime acquisition/hijack target.
- jQuery 1.7.1 bundles 5 unpatched XSS CVEs (all medium); version far below fixed_in=3.5.0.
- Privacy policy is Google's generic account policy — not scoped to this extension; data handling unknown.
- Free-webmail developer (gmail) with no verifiable business identity; no verified publisher badge.
- function_constructor + dynamic script creation in bundled jQuery raise code-quality risk under broad host access.
Evidence
- broad_host_access manifest *://*/ in host_permissions gives access to all URLs despite narrow stated function (stock alerts).
- zombie_extension store 38 months since last update (June 2023); maintenance pillar maxed at 10 + zombie booster N/A (<10K installs).
- cve_jquery_1.7.1 crx 5 medium CVEs in bundled jquery@1.7.1; fixed_in ranges 1.9.0–3.5.0; current version dangerously stale.
- generic_privacy_policy store Privacy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) → +10 privacy.
- free_webmail_developer store Developer email v71000@gmail.com; no verified publisher; no business domain; reputation floor applies.
- code_quality_findings crx function_constructor (×2) and script_src_dynamic in jquery bak/min files; dom_sink_innerhtml in active jquery.
- geo_diversity crx JS external hosts span 4 countries (CA, GB, IE, US); +1.5 network geo-diversity penalty applied.
- triple_stale_fingerprint crx >24mo stale + CVEs present + MV3 (MV2 penalty N/A); v2 calibration +2.0 webstore triple-stale applied.
CVE Exposures (5)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2012-6708 | jquery@1.7.1 | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2019-11358 | jquery@1.7.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.7.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-7656 | jquery@1.7.1 | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2015-9251 | jquery@1.7.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Stores user preferences locally; low risk.
- alarms low Schedules periodic stock price checks; expected for this tool.
- idle low Detects user idle state; minimal risk.
- notifications low Sends stock price alerts; core function, low risk.
- http://finance.sina.com.cn/ medium Specific stock data source; scoped host, acceptable for stated function.
- https://xueqiu.com/ medium Specific stock data source; scoped host, acceptable for stated function.
- http://image.sinajs.cn/ medium Image CDN for Sina Finance; scoped, acceptable.
- https://stock.xueqiu.com/ medium Specific stock API; scoped host, acceptable for stated function.
- http://qt.gtimg.cn/ medium Tencent stock quote API; scoped, acceptable.
- *://*/* high Broad host access — covers all URLs despite narrow stated function.
Pillar Scores
Permissions4.50
Reputation6.50
Network3.00
Webstore1.50
Maintenance10.00
Privacy10.00
Code Quality6.00
CVE Exposure5.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:04
Listing SHA
57bbb4ecfa01…
Force block
— not fired
Score recovered
no
Elapsed
—