Live editor for CSS, Less & Sass - Magic CSS
ifhikkcafabcgolfjegfcgloomalapol
Risk Score
5.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — does not scope data practices to this extension at all.
- eval_user_input and function_constructor in bundled Less compiler; arbitrary code execution risk if fed hostile input.
- dom_sink_innerhtml_userctrl combined with eval findings elevates DOM-XSS risk (FIX B).
- No developer name listed; gmail dev email with no verified business identity.
- 23 months since last update approaches stale threshold; verified-publisher discount capped under v3.5 invariant 0c (>18mo).
Evidence
- privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google generic policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D).
- eval_and_function_constructor crx eval_user_input (+2.5) and function_constructor (+2.5) found in Less compiler bundle; high code-quality risk.
- dom_sink_innerhtml_userctrl_elevated crx innerHTML sink present AND eval finding also present → +2.0 (FIX B).
- developer_identity store No developer name; gmail email webextensions.org@gmail.com; free-webmail dev raises reputation score.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied but capped at -1.0 due to >18mo staleness (invariant 0c).
- maintenance_staleness store 23 months since update → +6.0 maintenance pillar (6–12mo band overshoot; 12-24mo = +6.0).
- no_bad_hosts_or_cves crx cve_findings_raw empty, bad_host_hits empty, affiliate_hits empty, monetization_hits empty.
- csp_present_mv3 manifest script-src 'self'; object-src 'self' — strict CSP, MV3; no remote code loading penalty.
Permissions Breakdown
- activeTab medium Grants access to the active tab on user interaction; limited but enables DOM/script access.
- storage low Stores extension state locally; low direct risk.
- unlimitedStorage low Allows large local storage; minor abuse vector for data caching.
- scripting medium Can inject scripts into pages; necessary for CSS editor but elevated capability.
- offscreen low Creates offscreen documents for background processing; low risk without host perms.
Pillar Scores
Permissions2.30
Reputation5.50
Network1.50
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA
ff0fad84c219…
Force block
— not fired
Score recovered
no
Elapsed
30.0s