Equatio - Math made digital
hjngolefdpdnooamgdldlkjgmdcmcjnc
Risk Score
4.59
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- script_src_dynamic in multiple bundles: dynamic script injection across all_urls is a high-impact XSS vector.
- new Function() with DOM attribute input in mmlWorker/bundle.js — potential arbitrary code execution from page content.
- scripting + <all_urls>: broad programmatic script injection on every site the user visits.
- identity.email permission collects user PII (email); combined with broad host access raises exfil concern.
Evidence
- privacy_policy_generic store Privacy URL points to Google's own account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not extension-specific.
- script_src_dynamic_multiple_files crx Dynamic <script> element creation found in calculator/bundle.js, mathDiscoverGSuiteBundle.js, mathDiscoverabilityBundle.js, formBundle.js, mathjaxFrame/bundle.js.
- function_constructor_dom_attr crx new Function('item', e.getAttribute('jsTest')) in mmlWorker/bundle.js — executes DOM attribute as code.
- dom_innerHTML_sink crx innerHTML from variable in browserAction/bundle.js, htmlEditorApi.js, content/6067.js, mathjaxFrame/bundle.js — DOM-XSS sinks.
- broad_host_scripting manifest host_permissions=<all_urls> + scripting permission + content_scripts on <all_urls>; justified for Accessibility but high capability.
- is_featured_by_google store Google Featured badge present; reduces reputation risk but does not override code/privacy concerns.
- cve_findings_empty crx No CVEs detected in bundled libraries (jquery 3.5.1/3.6.0/3.7.1, react 16.13.1/17.0.2). CVE pillar = 0.
- sandbox_csp_unsafe_eval manifest sandbox CSP includes 'unsafe-eval' — eval permitted inside sandboxed frames, raises risk when combined with dynamic script loading.
Permissions Breakdown
- activeTab low Grants access to active tab on user action; scoped and low risk.
- tabs medium Can read tab URLs and metadata across sessions.
- alarms low Schedules background tasks; no data access.
- storage low Local/sync storage; no exfil risk alone.
- identity medium OAuth token access; can retrieve user identity tokens.
- identity.email medium Explicitly requests user email via OAuth — PII exposure.
- gcm low Push messaging; low direct risk but enables remote triggering.
- scripting high Programmatic script injection into pages; HIGH risk with <all_urls>.
- <all_urls> (host_permissions) high Broad host access across all sites; paired with scripting amplifies risk.
Pillar Scores
Permissions5.50
Reputation3.50
Network3.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality8.00
CVE Exposure0.00
Scoring History
| xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx | 4.77 | Medium | review | 2026-08-13 |
| 'fsssiedxa sssiedx | 4.68 | Medium | review | 2026-08-13 |
| fsssiedxa$"sssiedx | 4.66 | Medium | review | 2026-08-13 |
| <fsssiedxa"sssiedx | 4.86 | Medium | review | 2026-08-13 |
| <fsssiedxa$"sssiedx | 4.74 | Medium | review | 2026-08-13 |
| <fsssiedx{"sssiedx | 5.06 | Medium | review | 2026-08-02 |
| <fsssiedx{$"sssiedx | 5.22 | Medium | review | 2026-08-02 |
| xx pfsssiedxwfdsaxax><!--></ScRiPt>asddsssiedx | 4.68 | Medium | review | 2026-08-02 |
| %27fsssiedxw"sssiedx | 5.18 | Medium | review | 2026-08-02 |
| 4.64 | Medium | review | 2026-08-02 | |
| "fsssiedxwfdsaxax><!--></ScRiPt>asddsssiedx | 5.05 | Medium | review | 2026-08-02 |
| $"fsssiedxwsssiedx | 4.79 | Medium | review | 2026-08-02 |
| <fsssiedxhfdsaxax><!--></ScRiPt>asddsssiedx | 4.83 | Medium | review | 2026-08-02 |
| fsssiedx<sssiedx | 4.70 | Medium | review | 2026-08-02 |
| 'fsssiedxasssiedx | 4.14 | Medium | review | 2026-07-28 |
| fsssiedxa<sssiedx | 4.55 | Medium | review | 2026-07-28 |
| <fsssiedxh xx psssiedx | 4.73 | Medium | review | 2026-07-28 |
| <fsssiedxh$"sssiedx | 4.31 | Medium | review | 2026-07-28 |
| fsssiedxc"sssiedx | 4.49 | Medium | review | 2026-07-28 |
| sssieddrubricxsx | 4.10 | Medium | review | 2026-07-28 |
| v3.6 | 4.59 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 04:45
Listing SHA
f4b96233672e…
Force block
— not fired
Score recovered
no
Elapsed
—