AI Grammar and Spell Checker by Ginger
kdfieneakcjfaiglcfcgkidlkmlijjnh
Risk Score
6.21
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- angular@1.8.3 carries 1 high + 5 medium CVEs (XSS, ReDoS) with no fixed version available; AngularJS is EOL.
- Privacy policy fetched but scope_extension=false and admits third-party data sharing — worst-case Privacy pillar (10.0).
- cookies + <all_urls> host access on 500K-user AI extension; every page the user visits is in scope.
- CSP allows unsafe-eval on extension pages and sandbox; dynamic script creation found in code.
- Uninstall URL redirects to gingersoftware.com; monetization signals (GTM, GA) in CSP and external hosts.
Evidence
- angular@1.8.3 EOL with 9 CVEs (1 high, 5 medium, 3 low); no fixed_in version crx CVE-2024-21490 (high), CVE-2022-25869 (XSS moderate), plus 7 others — all unfixed.
- CSP unsafe-eval on extension_page and sandbox crx script-src includes 'unsafe-eval' in both extension_page and sandbox CSP directives.
- Privacy policy admits data collection + third-party sharing but not scoped to extension store scope_extension=false, data_collection=true, third_party_sharing=true per classification.
- cookies permission paired with host_permissions https://*/ and http://*/ manifest Broad cookie access across all sites; AI extension processes page text on all URLs.
- script_src_dynamic and function_constructor found in JS crx Dynamic script element creation in runtime JS; new Function() in writer.vendor.js.
- dom_sink_innerhtml_userctrl in multiple content script files crx innerHTML sinks in content.min.js, definitionPopup/main.js, popup.min.js, writer.min.js.
- uninstall_url_hijack to gingersoftware.com crx chrome.runtime.setUninstallURL points to https://www.gingersoftware.com/extension/uninstall?
- verified_publisher + is_featured_by_google; no sibling clusters; domain resolves store Positive signals cap reputation discount; 0c applies due to monetization_hits nonempty.
CVE Exposures (9)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2023-26117 | angular@1.8.3 | moderate | — | angular vulnerable to regular expression denial of service via the $resource ser |
| CVE-2023-26116 | angular@1.8.3 | moderate | — | angular vulnerable to regular expression denial of service via the angular.copy( |
| CVE-2024-21490 | angular@1.8.3 | high | — | angular vulnerable to super-linear runtime due to backtracking |
| CVE-2025-0716 | angular@1.8.3 | low | — | AngularJS improperly sanitizes SVG elements |
| CVE-2022-25844 | angular@1.8.3 | moderate | — | angular vulnerable to regular expression denial of service (ReDoS) |
| CVE-2024-8372 | angular@1.8.3 | low | — | AngularJS allows attackers to bypass common image source restrictions |
| CVE-2024-8373 | angular@1.8.3 | low | — | AngularJS allows attackers to bypass common image source restrictions |
| CVE-2022-25869 | angular@1.8.3 | moderate | — | Angular (deprecated package) Cross-site Scripting |
| CVE-2023-26118 | angular@1.8.3 | moderate | — | angular vulnerable to regular expression denial of service via the <input type=" |
Permissions Breakdown
- tabs medium Allows reading tab URLs and metadata across all open tabs.
- background medium Persistent background execution; increases attack surface lifetime.
- cookies high Can read/write cookies; paired with broad host access is HIGH×1.2 risk.
- storage low Local extension storage; low standalone risk.
- https://*/ high Broad host access to all HTTPS sites; combined with cookies is critical surface.
- http://*/ high Broad host access to all HTTP sites; extends reach to insecure origins.
- content_scripts <all_urls> high Content script injected into every page; full DOM read/write on all sites.
Pillar Scores
Permissions7.20
Reputation3.00
Network5.50
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality6.50
CVE Exposure8.25
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA
e1c2ccea37c8…
Force block
— not fired
Score recovered
no
Elapsed
51.9s