Boomerang for Gmail
mdanidgdpmkimeiiojknlnekblgmpdll
Risk Score
7.45
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
- Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true triggers +10.0 Privacy score.
- 6 medium-severity CVEs in bundled jquery@1.5.2 (far below fixed_in 3.5.0); no CSP amplifies XSS risk on Gmail DOM.
- Code findings: eval_user_input + function_constructor + script_src_dynamic in bookmarklet JS with no CSP.
- 'management' permission allows extension to enumerate/disable/uninstall other installed extensions.
Evidence
- management_permission manifest 'management' is HIGH-risk; allows disabling/uninstalling other extensions without user prompt.
- no_csp crx content_security_policy is null; MV3 default applies but no explicit lock-down; amplifies CVE/eval risk.
- jquery_cves crx jquery@1.5.2 carries 6 moderate CVEs; fixed versions range from 1.6.3 to 3.5.0; library is unpatched.
- eval_and_dynamic_script crx eval_user_input + function_constructor + script_src_dynamic all present in b4g_bookmarklet_1.8.7.js.
- privacy_policy_scope_mismatch store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic non-scoped policy.
- external_hosts_breadth crx 12 external JS hosts including s3.amazonaws.com, jsfiddle.net — wider than expected for an email scheduler.
- featured_by_google store Extension carries Google Featured badge; partial reputation credit applied.
- baydin_domain_resolves api developer_domain baydin.com resolves; looks_throwaway=false; no bad_host or affiliate hits.
Permissions Breakdown
- management high Can enumerate, disable, or uninstall other extensions — significant privilege.
- activeTab low Access only to the currently active tab on user gesture; limited scope.
- content_scripts: https://mail.google.com/* medium Injects JS into Gmail; appropriate for function but reads all email page content.
Pillar Scores
Permissions7.50
Reputation3.50
Network4.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality8.00
CVE Exposure5.25
Scoring History
| "fsssiedxefdsaxax><!--></ScRiPt>asddsssiedx | 4.71 | Medium | review | 2026-08-24 |
| fsssiedxe<sssiedx | 5.02 | Medium | review | 2026-08-24 |
| v3.69946/"();}]9598 | 5.09 | Medium | review | 2026-08-05 |
| v3.6"onmouseover=jFtY(96952)" | 4.44 | Medium | review | 2026-08-05 |
| dfb__${98991*97996}__::.x | 4.55 | Medium | review | 2026-08-05 |
| v3.6'"()&%<zzz><ScRiPt >jFtY(9389)</ScRiPt> | 4.55 | Medium | review | 2026-08-05 |
| v3.6&n952725=v997451 | 4.64 | Medium | review | 2026-08-05 |
| v3.6&n912981=v962801 | 5.16 | Medium | review | 2026-07-29 |
| sssieddrubricxsx | 5.09 | Medium | review | 2026-07-28 |
| v3.6 | 7.45 | High | block | 2026-06-15 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 13:43
Listing SHA
4983bf2f9f4c…
Force block
— not fired
Score recovered
no
Elapsed
53.7s