Extensity
jjmflmamggggndanpgfnpelongoepncg
Risk Score
7.00
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- Privacy policy is Google's generic account policy — not scoped to this extension; collects and shares data per policy.
- underscore@1.13.7 has a high-severity CVE (DoS via unlimited recursion); fix available in 1.13.8.
- management permission allows full control over all installed extensions — high-impact capability.
- Extension is 21 months stale; verified-publisher/featured discount capped at -1.0 under v3.5 invariant 0c.
Evidence
- management_permission manifest management declared — can enumerate/enable/disable all extensions on device.
- generic_google_privacy_policy store Privacy policy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
- high_cve_in_bundled_lib crx underscore@1.13.7 — CVE-2026-27601 high severity; fixed_in 1.13.8 not yet applied.
- function_constructor_in_libs crx new Function() in underscore-min.js and knockout-3.5.1.js; in library template/parse paths.
- stale_extension store Last updated Sep 2024; 21 months since update triggers +6.0 maintenance penalty.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discount capped at -1.0 (stale >18mo).
- brand_impersonation_signal store brand_mention: google referenced, is_impersonation=true, confirmed_owner=false.
- no_csp manifest csp_present=false on MV3; new Function() findings present — dom_sink amplifier applies.
CVE Exposures (1)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2026-27601 | underscore@1.13.7 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- management high Can enumerate, enable, disable, or uninstall all installed extensions — broad system control.
- storage low Local key-value storage; no cross-site or user-data risk on its own.
Pillar Scores
Permissions7.50
Reputation3.50
Network2.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality2.50
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA
b2fb1cf0a075…
Force block
— not fired
Score recovered
no
Elapsed
27.8s