KUARIO Print Anonymous
jhndfihagmlkccghdpjbhebhlnkmnioa
Risk Score
3.76
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy fetched but lacks extension scope and admits third-party data sharing — privacy pillar maxed.
- jQuery 3.4.1 bundles two medium CVEs (CVE-2020-11022, CVE-2020-11023); no CSP amplifies XSS risk.
- No content security policy (MV3 default strict but null CSP supplied) combined with vulnerable jQuery.
- Privacy policy references third-party sharing without scoping to this extension's data handling.
- Extension references external JS hosts (getbootstrap.com, popper.js.org) not covered by CSP.
Evidence
- CVE findings: jquery@3.4.1 with CVE-2020-11022 and CVE-2020-11023 (medium severity, fixed in 3.5.0) crx Two medium XSS CVEs in bundled jquery@3.4.1; no CSP present to mitigate DOM-based XSS risk.
- Privacy policy: fetched, scope_extension=false, data_collection=true, third_party_sharing=true store Policy admits data collection and third-party sharing but does not scope to this extension — D clause applies (+10.0).
- No content_security_policy declared manifest csp_present=false; MV3 provides default but null CSP with external hosts is a concern.
- External JS hosts: getbootstrap.com, github.com, popper.js.org, www.eclipse.org crx 4 distinct registrable domains referenced; all appear to be CDN/framework hosts, not threat-intel hits.
- Developer domain kuario.com resolves, looks_throwaway=false, no bad/affiliate/monetization hits api Clean threat intel; domain appears legitimate business.
- Maintenance: months_since_update=11 (6-12mo band) store Extension last updated July 31 2025; 6-12 month staleness window adds +3.5.
- No rating, no install count available store Missing popularity data; not penalized further but reduces reputation confidence.
- operator_cluster sibling_count=0, no wayback ownership change, no review red flags api No cluster risk, no ownership transfer detected, no negative review signals.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- printerProvider medium Allows extension to intercept print jobs; consistent with stated print function.
- activeTab low Temporary access to active tab only; low risk.
- windows low Can enumerate/manage browser windows; moderate but common for print UIs.
- tabs medium Can read tab URLs and metadata across open tabs.
- storage low Local extension storage only.
- https://kuario.com/* low Scoped to developer's own domain; consistent with print service backend.
- https://*.kuario.com/* low Scoped to developer's subdomains only.
Pillar Scores
Permissions2.30
Reputation5.00
Network2.00
Webstore0.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure2.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA
ac259b76030b…
Force block
— not fired
Score recovered
no
Elapsed
27.2s