Sprint Reader - Speed Reading Extension
kejhpkmainjkpiablnfdppneidnkhdif
Risk Score
4.49
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- 4 medium-severity CVEs in bundled jquery@2.0.3 (unfixed; fixed_in 3.5.0); known-bad-host hit on web.archive.org reference.
- Privacy policy is Google's generic account policy — not scoped to this extension, yet admits data collection and third-party sharing.
- 5 innerHTML DOM-XSS sinks across production and lib files combined with CVE-laden jQuery raise XSS chained-exploit risk.
- Content scripts injected on all http/https sites; gmail.com developer email means no verifiable business identity.
- Geo-diverse external JS hosts (4 countries) including languid.cantbedone.org and excamera.com — unusual for a reader extension.
Evidence
- jquery@2.0.3 — 4 moderate CVEs bundled, none patched crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; fixed_in 3.5.0, current 2.0.3.
- known-bad-host web.archive.org in js_external_hosts crx URLHaus malware_download hit on 154.216.19.139 associated with web.archive.org reference.
- Privacy policy is Google account generic policy store scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
- Developer email is free webmail (gmail.com), no business domain store anthonynosek@gmail.com; domain_age_ct not queried; no verified publisher badge.
- 5 innerHTML DOM-XSS sinks in production and lib files crx dom_sink_innerhtml_userctrl in facts.js, engine.js, reader.js, colorpicker, qunit.
- Content scripts on all http/https sites manifest content_scripts_matches: http://*/* and https://*/* — broad reach for a reader.
- 12 external JS hosts across 4 countries crx Hosts include languid.cantbedone.org, excamera.com, websvn.kde.org — geo-diversity count 4.
- is_featured_by_google=true partially offsets reputation risk store Featured badge applied; no verified publisher badge; free-webmail dev email remains.
CVE Exposures (5)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.0.3 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.0.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.0.3 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.0.3 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| web.archive.org | web.archive.org | high | — | [urlhaus/malware_download] URLHaus malware_download: 154.216.19.139,elf |
Permissions Breakdown
- contextMenus low Adds right-click menu items; limited blast radius.
- activeTab low Access limited to the current tab on user gesture.
- clipboardRead medium Can read clipboard content; text pasted for speed-reading plausible but sensitive.
- storage low Local preference storage; low risk.
- system.display low Read display metrics; useful for layout, no data exfil path.
- content_scripts http://*/* https://*/* medium Broad content-script injection on all sites; elevated reach for a reader extension.
Pillar Scores
Permissions3.30
Reputation6.50
Network1.50
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure6.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA
6b3d7aec7e60…
Force block
— not fired
Score recovered
no
Elapsed
38.8s