Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Linguix: Grammar Checker and AI Writing App

ndgklmlnheedegipcohgcbjhhgddendc
Risk Score
3.44
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category AI
Installs 30,000
Rating 4.5
Last updated 2026-09-07
Manifest version MV3
CSP present ✅ yes
Developer hi@linguix.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host access (*://*/*) with scripting permission allows reading/modifying content on every page visited.
  • AI/writing extension processes page text and sends it to linguix.com; third-party sharing admitted in privacy policy.
  • Privacy policy lacks data retention disclosure despite confirming data collection and third-party sharing.
  • Two DOM-XSS innerHTML sinks in content/popup scripts; no eval or remote loading, but CSP present mitigates partially.
  • No developer name listed in store; developer identity relies solely on hi@linguix.com and linguix.com domain.

Evidence

  • broad_host_access manifest host_permissions: *://*/*; content_scripts also match <all_urls>. Full read/write on every site.
  • ai_page_content_processing store AI writing/grammar assistant category; sends user text to linguix.com backend.
  • privacy_policy_gaps api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • dom_xss_sinks crx Two innerHTML assignments from variables in ext-content/main.js and ext-popup/main.js.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target not captured but runtime.setUninstallURL() called.
  • no_developer_name store developer_name is empty string; only hi@linguix.com and linguix.com domain identify the publisher.
  • featured_by_google store is_featured_by_google=true; provides partial trust signal, not verified publisher.
  • cve_clean crx cve_findings_raw empty; no known-bad hosts; no obfuscation (score=0.0).

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata; moderate privacy exposure.
  • storage low Local data persistence; low risk in isolation.
  • contextMenus low Adds right-click menu items; minimal risk.
  • clipboardWrite medium Can overwrite clipboard contents; moderate abuse potential.
  • clipboardRead medium Can read clipboard; sensitive data exposure risk.
  • scripting high Dynamic script injection into pages; high capability when paired with <all_urls>.
  • *://*/* high Broad host access across all sites; core reach for grammar/AI tool but high surface area.

Pillar Scores

Permissions5.50
Reputation4.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssiedn1e638bcfdp727562726963xsx 3.15 Low review 2026-09-09
v3.6 3.44 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA 9af1ce2e349c…
Force block — not fired
Score recovered no
Elapsed 23.6s