Web.archive.org Auto-Archiver
incoejagnokjhlkjkgpbdbooagggckdg
Risk Score
5.48
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- KNOWN_BAD_HOST: web.archive.org resolved to URLHaus-flagged IP (malware download); only JS external host.
- Abandoned: 37 months since last update, MV2, no CSP — stale extension with no oversight.
- Privacy policy is generic Google Sites page: admits data collection + third-party sharing, not scoped to this extension → maximum privacy risk.
- Developer is free-webmail gmail account with no verified identity or business presence.
- MV2 + no CSP: remote-code execution surface if extension is ever compromised or transferred.
Evidence
- known_bad_host api cve_findings_raw: web.archive.org flagged by URLHaus as malware_download host (154.216.19.139,elf), severity=high.
- stale_extension store Last updated July 2023; 37 months ago. MV2, no CSP. Triple-stale fingerprint triggers Webstore +2.0.
- generic_privacy_policy store Privacy policy on Google Sites; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- free_webmail_developer store Developer email mercermercer777@gmail.com; no verified publisher, no business website, numbered-alias pattern.
- mv2_no_csp manifest Manifest v2 with csp_present=false. v2 calibration +2.0 network penalty applied.
- cve_known_bad_host_amplifier api CVE pillar: KNOWN_BAD_HOST hit +2.0; high-severity +3.0 = 5.0 base. No amplifier (no DOM lib).
- reputation_free_webmail store Free webmail dev + no business site: floor at 7.5. Not verified publisher, not featured.
- install_count_low store Only 121 installs; no webstore-popularity bonus or trust discount applied.
CVE Exposures (1)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| web.archive.org | web.archive.org | high | — | [urlhaus/malware_download] URLHaus malware_download: 154.216.19.139,elf |
Permissions Breakdown
- https://web.archive.org/* medium Host access scoped to web.archive.org only; matches stated function but flagged KNOWN_BAD_HOST via URLHaus.
- tabs medium Can read active tab URL/title; moderate risk for an archiver needing current page URL.
Pillar Scores
Permissions1.30
Reputation7.50
Network4.00
Webstore0.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure5.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:24
Listing SHA
47b2106681ff…
Force block
— not fired
Score recovered
no
Elapsed
—