GetEmail.io gets the email of anyone on Earth
hbnjdgffjfjbkdoghlpkedjfoddlgbge
Risk Score
3.77
Risk Level:
Low
Recommendation:
🚫 BLOCK
Top Risks
- 18 CVEs in bundled lodash@4.8.2, underscore@1.8.3, jquery@2.1.1/3.4.1 including critical prototype pollution and arbitrary code execution — no CSP amplifies XSS risk.
- Privacy policy URL returns HTTP error (unfetchable) — treated as no policy; extension handles email/PII data with no verifiable disclosure.
- Install URL hijack redirects to a LinkedIn profile on install — onInstalled opens 3rd-party URL.
- No developer name listed; no verified publisher badge despite 90k installs and LinkedIn/email-harvest capability.
- 4 countries of JS host geo-diversity (CA, IE, IN, US) plus 12 external hosts including S3 and clearbit with no CSP restricting outbound connections.
Evidence
- cve_critical_lodash crx lodash@4.8.2 bundles CVE-2019-10744 (critical prototype pollution) and CVE-2021-23337 (high command injection); fixed_in 4.17.21 not met.
- cve_critical_underscore crx underscore@1.8.3 bundles CVE-2021-23358 (critical arbitrary code execution); fixed_in 1.12.1 not met.
- no_csp_with_vuln_libs manifest content_security_policy is null; MV3 with no explicit CSP and multiple DOM-manipulation libs with XSS CVEs.
- privacy_policy_unfetchable api privacy_policy_classification.fetched=false (HTTPError); policy cannot be evaluated — scored as no policy for email-harvesting tool.
- install_url_hijack crx install_url_hijack=true; onInstalled opens https://www.linkedin.com/in/mdell/ — 3rd-party URL redirect on install.
- no_developer_name store developer_name is empty string; no 'Offered by' identity; not a verified publisher despite 90k installs.
- innerHTML_dom_xss_sink crx dom_sink_innerhtml_userctrl in TabsView.js with no CSP and multiple jquery/lodash XSS CVEs — elevated DOM-XSS risk.
- geo_diversity_4_countries crx JS hosts span CA, IE, IN, US (4 countries); 12 external hosts including S3, clearbit, multiple getemail.io subdomains.
CVE Exposures (18)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-28500 | lodash@4.8.2 | moderate | 4.17.21 | Regular Expression Denial of Service (ReDoS) in lodash |
| CVE-2021-23337 | lodash@4.8.2 | high | 4.17.21 | Command Injection in lodash |
| CVE-2018-16487 | lodash@4.8.2 | high | 4.17.11 | Prototype Pollution in lodash |
| CVE-2026-2950 | lodash@4.8.2 | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2018-3721 | lodash@4.8.2 | moderate | 4.17.5 | Prototype Pollution in lodash |
| CVE-2019-10744 | lodash@4.8.2 | critical | 4.17.12 | Prototype Pollution in lodash |
| CVE-2020-8203 | lodash@4.8.2 | high | 4.17.19 | Prototype Pollution in lodash |
| CVE-2026-4800 | lodash@4.8.2 | high | 4.18.0 | lodash vulnerable to Code Injection via `_.template` imports key names |
| CVE-2019-1010266 | lodash@4.8.2 | moderate | 4.17.11 | Regular Expression Denial of Service (ReDoS) in lodash |
| CVE-2025-13465 | lodash@4.8.2 | moderate | 4.17.23 | Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions |
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@2.1.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.1.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Stores extension data locally; low risk on its own.
- activeTab low Access to current tab only on user action; scoped and transient.
- host: https://www.linkedin.com/* medium Content script on LinkedIn; can read/modify LinkedIn page data.
- host: https://*.getemail.io/* medium Broad access to all getemail.io subdomains for API calls.
Pillar Scores
Permissions1.30
Reputation6.50
Network3.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure10.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA
03440a9eb2d5…
Force block
— not fired
Score recovered
no
Elapsed
56.7s