Comunidade ZDG FREE
iofcjnefopghplghojjpglnjakejkein
Risk Score
6.27
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- browsingData + scripting + <all_urls>: can delete user data and inject JS into every site visited.
- 3 medium CVEs in jquery@3.3.1 (XSS); no CSP present, amplifying DOM-XSS risk across 9 innerHTML sinks.
- Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing.
- Free-webmail dev (zapdasgalaxias@gmail.com), no verified publisher, low rating 3.1; high-permission extension from unaccountable developer.
- 12 external JS hosts including raw.githubusercontent.com and third-party payment/analytics endpoints with no CSP guard.
Evidence
- broad_host_plus_scripting_browsingData manifest http://*/* + https://*/* with scripting and browsingData: can inject code and delete browsing data on any site.
- privacy_policy_generic_google store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — maps to +10 privacy score.
- jquery_cve_no_csp crx jquery@3.3.1 has 3 medium CVEs (XSS); no CSP present triggers v2 jquery@<3.5+no_CSP amplifier.
- innerHTML_sinks_multiple crx 9 files with dom_sink_innerhtml_userctrl; no CSP and CVEs present → each sink scores +2.0 (capped at 4.5 code quality).
- free_webmail_developer store Developer email zapdasgalaxias@gmail.com; no verified publisher badge, no featured badge, no business website.
- install_url_hijack manifest onInstalled opens https://web.whatsapp.com/ — install URL hijack to third-party site (+2.0 webstore).
- external_hosts_12 crx 12 distinct external JS hosts including raw.githubusercontent.com, payfast.greenn.com.br, davealger.info, darkwavetech.com.
- monetization_telemetry api google-analytics.com in monetization_hits; telemetry-tier only, category not adblock/shopping — +1.0 webstore.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- scripting high Arbitrary JS injection into pages; paired with <all_urls> host access = critical reach.
- declarativeNetRequest medium Can block/redirect network requests; moderate risk without redirect evidence.
- browsingData high Can delete cookies, history, cache — serious data destruction capability.
- activeTab low Scoped to user-activated tab; low risk in isolation.
- storage low Local extension storage; low risk.
- http://*/* high Broad host access over all HTTP sites; amplifies scripting and browsingData.
- https://*/* high Broad host access over all HTTPS sites; amplifies scripting and browsingData.
Pillar Scores
Permissions8.50
Reputation7.50
Network5.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 04:50
Listing SHA
4afc4b4abc44…
Force block
— not fired
Score recovered
no
Elapsed
—