Email Hunter
mbindhfolmpijhodmgkloeeppmkhpmhc
Risk Score
6.02
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Gmail developer with no business domain; privacy policy is generic Google account policy, not scoped to this extension.
- webRequest + scripting + <all_urls> gives full read/write capability on every page visited.
- Multiple medium CVEs in bundled jQuery 1.9.1 and 3.3.1 with no CSP — XSS amplifier active.
- No content security policy (MV3): CVE-bearing jQuery + no CSP elevates exploitability.
- 200K installs with high-capability permissions from an unverified free-webmail developer raises supply-chain risk.
Evidence
- free_webmail_developer store Developer is contacts.to.send@gmail.com — no verified business domain; reputation floor 7.5 applies.
- generic_privacy_policy store Privacy policy links to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
- cve_jquery_1.9.1 crx jquery@1.9.1 has 3 medium CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); no CSP present.
- cve_jquery_3.3.1 crx jquery@3.3.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); unfixed versions bundled.
- no_csp_with_cves manifest content_security_policy is null; CVE-bearing jQuery + no CSP triggers v2e +2.0 Code Quality amplifier.
- broad_host_permissions manifest <all_urls> host permission paired with webRequest and scripting = full-page surveillance + injection.
- function_constructor_code crx new Function() constructor found in lib/lib.js; +2.5 Code Quality per function_constructor signal.
- is_featured_by_google store Featured badge present; applied -2.0 Reputation discount but free-webmail floor overrides to 7.5.
CVE Exposures (6)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- notifications medium Can push notifications to user; medium nuisance/phishing risk.
- storage low Local data persistence only.
- alarms low Scheduled background tasks; low standalone risk.
- webRequest high Observe all network requests across all URLs; broad surveillance surface.
- webNavigation medium Tracks user navigation events across all sites.
- scripting high Programmatic script injection into any page via <all_urls>.
- <all_urls> (host_permissions) high Combined with scripting/webRequest gives full read/write on every site.
Pillar Scores
Permissions7.50
Reputation7.50
Network4.50
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality4.50
CVE Exposure5.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
972c5de6c2a9…
Force block
— not fired
Score recovered
no
Elapsed
30.3s