Annotate the Web
hkdbcemiphlcpmcphjgfaepgciimcoef
Risk Score
3.27
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- 7 moderate CVEs in bundled jquery@3.3.1 and jquery-ui@1.12.1 (multiple XSS vectors, all unpatched).
- <all_urls> host permission + scripting enables content injection on every site visited.
- Privacy policy hosted on Google Sites, no data retention disclosed, third-party sharing silence.
- Doubleclick/Google Analytics telemetry endpoints in CSP; doubleclick is ad-tier beyond pure analytics.
- Description promises 'recording' but lacks tabCapture/desktopCapture — minor permission mismatch.
Evidence
- multiple_moderate_cves crx 7 moderate CVEs across jquery@3.3.1 (3) and jquery-ui@1.12.1 (4); all below fixed_in versions.
- host_permissions_all_urls manifest <all_urls> paired with scripting and content_scripts; broad page access for annotation tool.
- monetization_hits crx stats.g.doubleclick.net in js_external_hosts — ad-tech tier beyond analytics telemetry.
- privacy_policy_google_sites store Policy on sites.google.com; scope_extension=true but retention=false, third_party_silence=true.
- description_promise_mismatch store Description says 'save as screenshot' but also implies recording without tabCapture permission.
- no_obfuscation_clean_code crx obfuscation_score=0.0, code_findings_raw empty; code itself is clean.
- csp_present_mv3 manifest script-src 'self'; object-src 'self' — restrictive CSP, MV3. No unsafe-eval/inline.
- developer_domain_resolves api ps109x.org resolves, looks_throwaway=false, no bad_host_hits, sibling_count=0.
CVE Exposures (7)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-41182 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `altField` option of the Datepicker widget in jquery-ui |
| CVE-2021-41184 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `of` option of the `.position()` util in jquery-ui |
| CVE-2022-31160 | jquery-ui@1.12.1 | moderate | 1.13.2 | jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in |
| CVE-2021-41183 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in `*Text` options of the Datepicker widget in jquery-ui |
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- activeTab low Scoped to user-initiated interactions only; lower risk than broad host access.
- storage low Local data persistence; no exfiltration risk on its own.
- scripting medium Can inject scripts into pages; elevated when combined with <all_urls> host permission.
- <all_urls> (host_permission) high Grants access to every site the user visits; broad attack surface for annotation/screenshot use.
Pillar Scores
Permissions3.50
Reputation5.00
Network3.50
Webstore3.00
Maintenance1.50
Privacy2.00
Code Quality0.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA
2422bd4c584e…
Force block
— not fired
Score recovered
no
Elapsed
29.8s