NaturalReader - AI Text to Speech
kohfgcgbkjodfcfkcackpagifgbcmimk
Risk Score
5.26
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- jquery@1.9.1 bundled with 3 moderate CVEs (XSS); fixed version is 3.5.0 — far behind current.
- Dynamic <script src> injection in content script running on <all_urls> enables remote code execution risk.
- Privacy policy fetched but does not scope to this extension or disclose what data is collected (+9.0 privacy score).
- Multiple innerHTML DOM-XSS sinks in injected scripts active on every page visited.
- brand_mention flags 'google' impersonation; no developer name listed and not a verified publisher.
Evidence
- jquery@1.9.1 with 3 moderate CVEs present in bundled bootstrap crx jquery 1.9.1 detected via inline-marker in bootstrap.bundle.min.js; CVE-2015-9251, CVE-2019-11358, CVE-2020-11023 unpatched.
- script_src_dynamic in content script with <all_urls> crx nr-ext-dom-detector.js dynamically appends <script src=...> tags on every visited page.
- Privacy policy not scoped to extension; data_collection=false but scope_extension=false api PDF policy at naturalreaders.com/media/privacy2.pdf does not reference extension or specify collection scope.
- No developer name; brand impersonation flag on 'google' store developer_name is empty; brand_mention.is_impersonation=true for 'google'; not a verified publisher.
- <all_urls> host permission with content_scripts on all sites manifest content_scripts_matches includes <all_urls>; scripting+webNavigation+tabs compound the broad reach.
- 12 distinct external JS hosts including 7 AWS API Gateway endpoints crx js_external_hosts has 12 entries; multiple opaque execute-api.us-east-1.amazonaws.com subdomains contacted.
- function_constructor in 4 background/injected files crx new Function() used in amplify-config.js, ocr.js, online-tts.js, injected/amplify-config.js.
- Featured by Google; MV3; CSP present; no bad/affiliate/monetization hosts store is_featured_by_google=true, MV3, CSP script-src self, threat_intel all clean — mitigating factors.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- scripting medium Can inject scripts into pages; moderate risk especially combined with <all_urls>.
- activeTab low Temporary access to active tab only; low standalone risk.
- contextMenus low Adds right-click menu items; minimal risk.
- storage low Local extension storage; low risk.
- tts low Text-to-speech output only; core function, low risk.
- ttsEngine low Provides TTS engine; core function, low risk.
- webNavigation medium Observes navigation events across all URLs; surveillance potential.
- tabs medium Access to tab URLs and metadata across browsing session.
- <all_urls> (host_permission) high Content scripts inject into every page; broad access amplifies all other risks.
Pillar Scores
Permissions5.50
Reputation5.50
Network3.50
Webstore3.50
Maintenance1.50
Privacy9.00
Code Quality7.00
CVE Exposure3.00
Scoring History
| sssiedn9f538212dp727562726963xsx | 4.84 | Medium | review | 2026-09-07 |
| sssiedn79d6dae0dp727562726963xsx | 5.00 | Medium | review | 2026-09-06 |
| <fsssiedxi xx psssiedx | 4.73 | Medium | review | 2026-08-17 |
| <fsssiedxa$"sssiedx | 5.59 | Medium | review | 2026-08-17 |
| %27fsssiedxa$'sssiedx | 4.93 | Medium | review | 2026-08-15 |
| fsssiedxa<sssiedx | 4.85 | Medium | review | 2026-08-15 |
| <fsssiedxa sssiedx | 5.17 | Medium | review | 2026-07-29 |
| fsssiedx<sssiedx | 4.76 | Medium | review | 2026-07-29 |
| sssieddrubricxsx | 4.93 | Medium | review | 2026-07-29 |
| v3.6 | 5.26 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA
5d6bd478a5ee…
Force block
— not fired
Score recovered
no
Elapsed
38.1s