Webpage Spell-Check
mgdhaoimpabdhmacaclbbjddhngchjik
Risk Score
6.59
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- jquery@1.12.4 bundles 4 medium CVEs (XSS); no CSP to mitigate; version far below fixed_in 3.5.0
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension
- Extension not updated in 31 months (zombie); stale CVE-laden jQuery poses persistent XSS risk
- Broad content_script on all HTTP/HTTPS pages with innerHTML sink — DOM-XSS vector on every site
- Gmail dev, no developer name, low rating 2.7; verified publisher but no recognized org identity
Evidence
- jquery_cve_cluster crx 4 medium CVEs in jquery@1.12.4 (CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
- no_csp manifest content_security_policy is null; no CSP mitigation for DOM-XSS or dynamic script loading.
- privacy_policy_inadequate store Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — generic admitting policy.
- stale_extension store Last updated November 2023; 31 months since update. Triggers 24-36mo maintenance band (+8.5).
- broad_host_access_content_script manifest content_scripts_matches http://*/* and https://*/* — runs on every page visited.
- dom_xss_sink crx innerHTML assigned from variable in spellcheck-extension.js with no CSP and CVEs present — elevated DOM-XSS risk.
- free_webmail_dev_no_name store developer_email=gakbar@gmail.com, developer_name empty; verified_publisher=true caps floor at 2.0.
- low_rating store Rating 2.7; count unknown but signal is negative user sentiment.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.12.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@1.12.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.12.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Stores extension settings locally; limited blast radius.
- http://*/* high Broad host access to all HTTP pages via content_scripts; enables DOM manipulation on every site.
- https://*/* high Broad host access to all HTTPS pages; same risk surface as http://*/*.
Pillar Scores
Permissions5.50
Reputation7.00
Network3.00
Webstore3.50
Maintenance8.50
Privacy10.00
Code Quality5.50
CVE Exposure6.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA
61b88b3c63f6…
Force block
— not fired
Score recovered
no
Elapsed
28.8s