Writing Assistant
icfibfjidabjcklhikmodelmopjmghgj
Risk Score
5.12
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing without scoping to this extension — scores maximum privacy risk.
- Content script runs on <all_urls> giving access to every page; no CSP amplifies innerHTML XSS sinks.
- Uninstall URL hijack detected — extension redirects user on uninstall to undisclosed third-party URL.
- 19 months since last update; no active maintenance signal for an AI extension touching all pages.
- AI writing assistant with broad page access, weak privacy posture, and low rating (3.2) raises data-exfil concern.
Evidence
- content_scripts_all_urls manifest content_scripts_matches includes <all_urls> — extension JS runs on every site visited.
- privacy_policy_third_party_sharing crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (D).
- uninstall_url_hijack crx uninstall_url_hijack=true; target unknown. Adds +3.0 webstore.
- no_csp manifest content_security_policy is null; csp_present=false — amplifies innerHTML XSS findings.
- dom_sink_innerhtml_userctrl_no_csp crx Two innerHTML sinks with csp_present=false trigger +2.0 code quality each (FIX B) — capped.
- maintenance_stale store 19 months since update — falls in 12-24mo band (+6.0).
- is_featured_by_google store Featured badge present; partially offsets reputation risk.
- low_rating store Rating 3.2; rating_count not provided — no threshold discount applies.
Permissions Breakdown
- storage low Stores local extension data; low intrinsic risk.
- content_scripts:<all_urls> high Content script injected on all URLs — reads/modifies every page the user visits.
Pillar Scores
Permissions3.50
Reputation4.50
Network4.00
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:41
Listing SHA
e1a55e2c03da…
Force block
— not fired
Score recovered
no
Elapsed
23.8s