CSS validator
hhlcpmdhlcoghhfgiiopcjbkfmdliknc
Risk Score
5.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — does not scope to this extension; admits data collection and 3rd-party sharing (+10 privacy).
- Uninstall URL hijack flagged (uninstall_url_hijack=true) and install URL hijack to cssvalidator.app/welcome — monetization/tracking risk.
- No developer name listed; missing 'Offered by' accountability signal.
- Extension stale 21 months (6-12mo band) with no changelog visible.
- DOM-XSS sink (innerHTML from variable) in bundled ace.js with no CSP present.
Evidence
- uninstall_url_hijack crx uninstall_url_hijack=true; install_url_hijack=true targeting https://cssvalidator.app/welcome — redirect tracking on lifecycle events.
- generic_privacy_policy store Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true — generic and admits broad data sharing.
- no_developer_name store developer_name is empty; no verified publisher badge; reduced accountability.
- stale_extension store Last updated November 2024; months_since_update=21 — falls in 12-24mo band (+6.0 maintenance).
- dom_xss_sink crx innerHTML assignment from variable in lib/ace/src/ace.js; no CSP present, elevating DOM-XSS risk.
- external_hosts crx JS contacts cssvalidator.app, github.com, headlinegenerator.app — headlinegenerator.app is unrelated to CSS validation.
- no_csp crx content_security_policy is null; csp_present=false for MV3 extension with DOM-sink finding.
- install_url_hijack crx install_url_hijack=true; target https://cssvalidator.app/welcome — Webstore +2.0 per rule.
Permissions Breakdown
- storage low Local key-value store only; no cross-origin data access.
Pillar Scores
Permissions0.80
Reputation6.50
Network0.00
Webstore6.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 10:43
Listing SHA
6e541bcd7963…
Force block
— not fired
Score recovered
no
Elapsed
—