Upvote First for StackOverflow
jafbgebfjkfejghbdeohaadmfghkmjlo
Risk Score
5.50
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- jQuery 3.1.0 bundles 3 medium CVEs (XSS); no CSP and no update in 50 months amplifies exposure.
- Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true — admits broad data sharing without scoping to this extension.
- Developer uses free webmail (gmail) with no verified business domain; brand_mention flags StackOverflow impersonation.
- Extension abandoned: 50 months since last update with unfixed vulnerable dependency.
- No content security policy on MV3 extension with externally referenced JS hosts (github.com, jqueryui.com).
Evidence
- jquery@3.1.0 — 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), fixed in 3.5.0 crx Bundled vulnerable jQuery not updated in 50 months; no CSP amplifies XSS risk per v2 jquery+no-CSP rule.
- Privacy policy admits data_collection=true + third_party_sharing=true but scope_extension=false store v3.5(D): policy fetched, not scoped to extension, admits collection+3rd-party sharing => +10.0 privacy.
- Abandoned extension: 50 months since last update store months_since_update=50 exceeds 36-month threshold; zombie booster does not apply (installs<10K).
- Brand impersonation: StackOverflow mentioned, confirmed_owner=false, dev=gmail store brand_mention.is_impersonation=true, not verified publisher, not featured by Google => +2.0 reputation.
- Free webmail developer (gmail) with no business domain store jossef12@gmail.com; no developer domain resolved; +1.5 reputation for free-webmail dev.
- No CSP on MV3 extension with external JS hosts crx csp_present=false; js_external_hosts=[github.com, jqueryui.com]; no MV2+no-CSP network penalty (MV3).
- is_featured_by_google=true — partial reputation mitigation store Featured badge applied; -2.0 reputation discount but impersonation and gmail dev floor reputation at 7.0.
- Content scripts scoped to StackExchange network only; no broad host access mismatch crx Permissions match stated function; install_perm_anomaly.small_install_high_perm=false.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.1.0 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.1.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.1.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- background low Allows background processing; low risk without high-impact paired permissions.
- storage low Local data storage only; no exfil risk by itself.
- host:*.stackoverflow.com + StackExchange network medium Content scripts run on all SE network domains; scoped to stated function but broad within that network.
Pillar Scores
Permissions1.30
Reputation7.00
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA
956b0a4252a3…
Force block
— not fired
Score recovered
no
Elapsed
29.0s