Recipes Stash
jepcdjidlnpjfdblhhkkfhgbgdgphile
Risk Score
4.74
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension — generic policy with full disclosure gap.
- Default search provider override silently redirects all browser searches through recipesstash.com, capturing query data.
- Bundled jquery@3.3.1 has 3 medium XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), no CSP present to mitigate.
- No developer name listed; 22 months since last update raises abandonment and supply-chain risk.
- MV3 + no CSP with vulnerable jQuery in popup context increases DOM-XSS exploitability.
Evidence
- search_provider_override manifest chrome_settings_overrides sets recipesstash.com as default search (is_default=true); all queries routed there.
- privacy_policy_generic_with_third_party_sharing crx Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
- jquery_cve_medium_x3 crx jquery@3.3.1 in popup/jquery.min.js has 3 medium CVEs; fixed_in 3.5.0. No CSP to block exploitation.
- no_csp manifest content_security_policy is null; csp_present=false. v2b: MV3 strict default applies, no additional penalty.
- stale_extension store 22 months since update (6-24mo band); +6.0 maintenance. No changelog visible.
- no_developer_name store developer_name is empty string; identity accountability reduced. +1.0 reputation.
- triple_stale_fingerprint store >18mo stale + CVEs present + MV3 (not MV2 so v2c MV2 requirement not met; no additional +2.0 applied).
- obfuscation_clean crx obfuscation_score=0.0, code_findings_raw empty; no malicious JS patterns detected.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- search medium Allows overriding search provider; paired with chrome_settings_overrides to set default search.
- host_permissions: https://recipesstash.com/* low Scoped to single developer-controlled domain only.
- chrome_settings_overrides.search_provider (is_default=true) medium Sets recipesstash.com as default search engine silently; monetization risk via search query capture.
Pillar Scores
Permissions3.00
Reputation6.50
Network0.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:21
Listing SHA
058a4b8b6a99…
Force block
— not fired
Score recovered
no
Elapsed
—