BeeLine Reader
ifjafammaookpiajfbedmacfldaiamgg
Risk Score
4.98
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — not scoped to this extension; data collection and 3rd-party sharing admitted without extension-specific disclosure.
- jquery@3.4.1 bundles two medium CVEs (CVE-2020-11022, CVE-2020-11023) with no CSP, amplifying XSS risk across all sites visited.
- No CSP declared (MV3); dom_sink_innerhtml_userctrl found in 3 files including readability.js and React DOM, all active on every site.
- Broad host access *://*/* with scripting permission enables full read/write on all pages; uninstall URL redirects to Google Forms survey.
- No developer name listed; privacy policy is a generic Google account policy with third_party_sharing=true and no extension scope.
Evidence
- privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- cve_medium_jquery crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (both moderate XSS); fixed_in 3.5.0. No CSP amplifies risk.
- dom_sink_no_csp crx dom_sink_innerhtml_userctrl in 3 files with csp_present=false triggers elevated code-quality scoring (FIX B).
- broad_host_scripting manifest host_permissions *://*/* + scripting + content_scripts on http/https://*/* gives full page read/modify on all sites.
- uninstall_url_hijack crx uninstall_url_hijack=true; target is a Google Forms survey URL — low severity but flagged.
- no_developer_name store developer_name is empty string; only email contact@beelinereader.com provided. +1.0 reputation.
- featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount (Featured / follows recommended practices).
- react_below_16_4_no_csp crx react@16.12.0 bundled (below 16.4 threshold n/a; 16.12>16.4). No CVE amplifier applies for react version. Noted for completeness.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Access to tab URLs/titles; medium risk but standard for reader-mode extensions.
- storage low Stores user preferences locally; low risk.
- scripting high Programmatic script injection into pages; high risk when paired with *://*/* host access.
- *://*/* high Broad host access to all HTTP/HTTPS sites; enables reading/modifying all page content.
Pillar Scores
Permissions5.30
Reputation5.50
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality4.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA
3e3b819c3473…
Force block
— not fired
Score recovered
no
Elapsed
30.6s