grt memo
hjepgjomhnddghfkpoibmjpofhkbagkm
Risk Score
4.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- jquery@2.0.3 bundles 4 moderate CVEs (XSS); fixed versions available up to 3.5.0.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- No CSP present on MV3 extension with known-vulnerable DOM-manipulation library (jquery).
- Developer name is blank; identity accountability is weak despite verified publisher status.
- Extension updated 11 months ago; bundled vulnerable jquery not remediated.
Evidence
- cve_findings_raw: 4 moderate CVEs in jquery@2.0.3 crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; all fixed in >=3.5.0, bundled version 2.0.3.
- privacy_policy_classification: Google generic policy, not extension-scoped store scope_extension=false, data_collection=true, third_party_sharing=true → scores +10.0 (D rule).
- csp_present: false on MV3 extension with vulnerable jquery manifest No content_security_policy declared; jquery+no-CSP combo triggers v2e rule.
- developer_name: empty string store No 'Offered by' name displayed; reduces accountability despite verified_publisher=true.
- verified_publisher: true; groundroad.com resolves, not throwaway store Verified publisher discount applied but capped at -1.0 due to monetization/stale checks N/A; full -3.0 applied here (no stale/CVE cap trigger on publisher discount per 0c: CVE present caps at -1.0).
- installs: 80,000 — moderate blast radius store +1.0 webstore for >10K installs.
- months_since_update: 11 — in 6-12mo band store Maintenance +3.5; vulnerable jquery not updated in ~11 months.
- js_external_hosts: twitter.com, www.apache.org crx 2 external hosts referenced; no bad-host or monetization hits; network risk low.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.0.3 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.0.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.0.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.0.3 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- tabs medium Can read tab URLs and titles; moderate info-disclosure risk.
- unlimitedStorage low Allows storing large data locally; no direct exfil vector.
Pillar Scores
Permissions1.30
Reputation4.00
Network2.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA
5922744145b2…
Force block
— not fired
Score recovered
no
Elapsed
28.1s