Word Counter - counts what you type
hjnjgdaeojdfoajjigipjmdnailbmfje
Risk Score
4.52
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Abandoned extension (37+ months since last update) with 3 unpatched medium CVEs in bundled jQuery 3.3.1.
- Content script injected on ALL URLs despite simple word-counter function — broad unnecessary reach.
- No CSP present; jQuery XSS CVEs combined with no-CSP amplifies exploitation surface on every page.
- Privacy policy discloses third-party data sharing without scoping specifically to this extension's data.
- Uninstall URL hijack flag set; destination not captured but warrants inspection.
Evidence
- stale_extension store Last updated May 2022; ~37 months ago. Maintenance pillar capped at 10.0.
- cve_jquery_3_3_1 crx 3 medium CVEs in jquery@3.3.1 (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
- no_csp crx content_security_policy is null (MV3 default enforced, but no explicit hardening; amplifies jQuery CVE risk).
- content_scripts_all_urls manifest content_scripts_matches includes <all_urls>; over-broad for word-counter category.
- uninstall_url_hijack crx uninstall_url_hijack == true; target not captured. Webstore +3.0 penalty applied.
- third_party_sharing_policy store Privacy policy: fetched, scoped, data_collection=true, third_party_sharing=true, retention=true.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied but capped per 0c (stale>18mo + CVEs).
- js_external_hosts crx 8 external hosts referenced in JS: paypal.com, wordpress.com, c306.net, github.com, etc. (3 countries).
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Stores user preferences/word counts locally; expected for this category.
- content_scripts:<all_urls> high Content script injected on every site; broad reach for a word-counter, no host restriction.
Pillar Scores
Permissions2.80
Reputation2.00
Network2.50
Webstore4.00
Maintenance10.00
Privacy1.00
Code Quality2.00
CVE Exposure5.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 06:17
Listing SHA
3908822a9aab…
Force block
— not fired
Score recovered
no
Elapsed
488.0s