OneNote Web Clipper
gojbdfnpnhogfdgjbigejoaolejmgdhk
Risk Score
4.15
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- webRequest + <all_urls>: can observe all HTTP requests across every site user visits.
- Privacy policy fetch failed (HTTP error); data handling for this extension unverifiable.
- innerHTML sink in rangy-core.js could enable DOM-XSS if input not sanitized.
- new Function() in pdf.combined.js is a dynamic code execution risk.
- 12 external JS hosts in CSP including github.io and third-party domains beyond microsoft.com.
Evidence
- webRequest+<all_urls> manifest webRequest permission with <all_urls> host_permissions enables full network observation on every site.
- privacy_policy_fetch_failed api privacy_policy_classification.fetched=false due to HTTPError; policy content unverifiable; scored +10.0.
- is_featured_by_google store Extension carries Google Featured badge; applied -2.0 reputation discount.
- microsoft_developer_domain store dev email @microsoft.com; recognized org -2.0 discount applied; capability gate checked (webRequest present).
- capability_gate_v2b manifest Recognized-org discount capped at -1.0 per v2 calibration: extension exercises HIGH-impact capability (webRequest, <all_urls>).
- code_finding_function_constructor crx new Function() in pdf.combined.js; +2.5 code quality signal.
- code_finding_innerhtml crx dom_sink_innerhtml_userctrl in rangy-core.js; CSP present so +0.5 not elevated to +2.0.
- external_hosts_12 crx 12 distinct external JS hosts including bestiejs.github.io, peter.michaux.ca, kit.mit-license.org; >3 distinct domains.
Permissions Breakdown
- activeTab low Scoped to user-invoked tab only; low blast radius.
- scripting medium Can inject JS into pages; paired with activeTab limits scope but still significant.
- contextMenus low UI surface only, no data access.
- tabs medium Can read tab URLs and metadata across all tabs.
- webRequest high Can observe all network requests across <all_urls>; broad surveillance capability.
- webNavigation medium Can observe navigation events; combines with tabs for browsing history.
- offscreen low Offscreen document for DOM processing; limited risk alone.
- <all_urls> (host_permissions) high Grants access to every site; amplifies webRequest and scripting risk.
Pillar Scores
Permissions5.50
Reputation2.00
Network2.50
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality3.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA
a1fe4fdc95c6…
Force block
— not fired
Score recovered
no
Elapsed
37.8s