Grammarly: AI Writing Assistant and Grammar Checker App
kbfnbcaeplbcioakkpcpgfkobkghlhen
Risk Score
5.25
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but scope_extension=false and admits data_collection+third_party_sharing — generic corporate policy, not extension-scoped (Privacy=10.0).
- Broad host permissions (http://*/*, https://*/*) combined with cookies permission enables access to session tokens on every site visited.
- AI writing assistant reads text from all websites including sensitive/confidential content on all 38M installs.
- Three innerHTML DOM-XSS sinks in production JS — CSP present mitigates but does not eliminate risk from page-content injection.
- No verified publisher badge and developer_name empty — despite grammarly.com domain, formal publisher verification absent.
Evidence
- broad_host_permissions manifest http://*/* and https://*/* grant content-script injection on every site; cookies permission amplifies to session-token risk.
- privacy_policy_not_extension_scoped crx policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (v3.5 rule D).
- dom_xss_sinks crx 3 innerHTML findings in vendors+inkwell chunks; CSP present (script-src 'self') reduces exploitation path but sinks exist.
- ai_extension_page_content store AI writing assistant processes text on all visited pages; +2.5 AI webstore signal applied.
- no_verified_publisher store verified_publisher=false, developer_name empty; is_featured_by_google=true reduces reputation risk partially.
- cookies_high_perm manifest cookies + <all_urls> host access is HIGH×1.2 multiplier surface.
- connect_src_broad crx CSP connect-src lists 40+ endpoints including S3, Iterable, Superhuman, CloudFront — diverse external connectivity.
- react_17_bundled crx React 17.0.2 bundled; no CVEs found in cve_findings_raw, no score impact.
Permissions Breakdown
- scripting medium Can inject JS into pages; paired with broad host_permissions amplifies risk.
- sidePanel low UI surface only, low direct risk.
- tabs medium Access to tab URLs and metadata across all open tabs.
- notifications low Can display notifications; limited abuse surface.
- cookies high Read/write cookies; combined with broad host access enables session token access.
- identity medium OAuth token access; scoped but can expose user identity.
- storage low Local extension storage only.
- http://*/* high Broad host permission — content scripts run on all HTTP sites.
- https://*/* high Broad host permission — content scripts run on all HTTPS sites, including banking/email.
Pillar Scores
Permissions7.50
Reputation3.00
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| sssiedn0a5fd568dp727562726963xsx | 4.42 | Medium | review | 2026-08-30 |
| fsssiedxa"sssiedx | 4.66 | Medium | review | 2026-08-07 |
| sssieddrubricxsx | 4.73 | Medium | review | 2026-08-07 |
| %76%33%2E%36%39%38%30%39%22%28%29%3B%7D%5D%39%37%30%34 | 4.87 | Medium | review | 2026-08-05 |
| <%={{={@{#{${dfb}}%> | 5.26 | Medium | review | 2026-08-05 |
| v3.6&n973472=v914877 | 4.92 | Medium | review | 2026-08-05 |
| v3.6 | 5.25 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:47
Listing SHA
cf81f8a10596…
Force block
— not fired
Score recovered
no
Elapsed
29.0s