Find The Recipe
naaffooocnnodpcmppdjhpjiogkljkch
Risk Score
5.34
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Search provider override (is_default=true) silently redirects ALL omnibar queries to findtherecipe.com.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
- Bundled jquery@3.3.1 carries 3 moderate XSS CVEs (fixed in 3.5.0), extension not updated in 22 months.
- No developer name listed; developer identity accountability is low.
- Extension stale 22 months with known-vulnerable library and no CSP on popup, raising XSS exploitation risk.
Evidence
- search_provider_override manifest chrome_settings_overrides.search_provider.is_default=true routes all searches to findtherecipe.com/ext/search.
- privacy_policy_inadequate crx Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — admits sharing without extension scope.
- cve_jquery_3.3.1 crx 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) in bundled jquery@3.3.1; fixed in 3.5.0.
- stale_extension store Last updated November 2024, 22 months ago; vulnerable library not patched.
- no_developer_name store developer_name is empty; no 'Offered by' identity shown in store listing.
- no_csp manifest content_security_policy is null; MV3 default applies but popup uses jquery with XSS CVEs and no explicit CSP.
- no_rating store Rating 0 with 0 ratings on 9,000 installs; no community trust signal.
- v2_calibration_search_override_permissions manifest Search-provider override scored +2.0 on Permissions per rubric rule (a) for chrome_settings_overrides.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- search medium Allows overriding the default search engine; paired with chrome_settings_overrides it redirects all searches.
- chrome_settings_overrides.search_provider (is_default=true) high Forces itself as default search engine, capturing every omnibar query and routing through findtherecipe.com.
- host_permissions: https://findtherecipe.com/* low Narrow host permission scoped to developer's own domain only.
Pillar Scores
Permissions5.00
Reputation6.00
Network2.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 06:15
Listing SHA
aab31c0e331d…
Force block
— not fired
Score recovered
no
Elapsed
—