Writer
hngnkmianenpifegfoggnkamjnffiobn
Risk Score
5.76
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: arbitrary code execution); no CSP amplifies exploitability.
- Privacy policy fetched but scope_extension=false AND data_collection+third_party_sharing=true — admits broad data sharing without scoping to this extension.
- cookies + scripting + broad host_permissions (<all_urls>) allows reading auth cookies and injecting JS on every site.
- new Function() constructor used in 4 JS files — dynamic code execution risk, especially without CSP.
- AI extension processing page content across all URLs; 6 distinct external JS hosts contacted at runtime.
Evidence
- cve_critical_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (critical, ACE); fixed in 1.12.1. No CSP present — v2 amplifier applies.
- privacy_policy_scope_mismatch store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.0 privacy.
- broad_host_cookies_scripting manifest cookies + scripting + http://*/ + https://*/ — can exfiltrate auth cookies from any site.
- function_constructor_no_csp crx new Function() in 4 files; csp_present=false — dynamic code execution without CSP mitigation.
- ai_extension_page_content store Described as generative AI; content_scripts on <all_urls> — processes content on every visited page.
- no_developer_name store developer_name is empty string; dev email waseem@writer.com on writer.com domain which resolves.
- 6_external_js_hosts crx Contacts api.statsigcdn.com, featureassets.org, github.com, prodregistryv2.org, reactjs.org, support.writer.com.
- featured_by_google store is_featured_by_google=true; not verified_publisher. Partial trust signal, no verified discount.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- tabs medium Can enumerate open tabs and their URLs.
- cookies high Read/write cookies across origins; paired with broad host access amplifies risk.
- storage low Local extension storage; low risk alone.
- scripting high Can inject JS into any page given broad host_permissions.
- sidePanel low UI surface only; low risk.
- http://*/ high Broad host access over all HTTP origins.
- https://*/ high Broad host access over all HTTPS origins; cookies+scripting+<all_urls> combo ×1.2.
Pillar Scores
Permissions7.50
Reputation4.00
Network5.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:40
Listing SHA
f6161908042f…
Force block
— not fired
Score recovered
no
Elapsed
33.5s