Highlight
nffionklkilbohdkhcmkbbkofhkbmggl
Risk Score
4.44
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); unfixed.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension (score 10).
- brand_mention flags Google impersonation but developer domain is kickdrumtech.com, not Google.
- desktopCapture permission can record screen/audio; high-capability for a Docs annotation tool.
- No developer name listed; identity accountability gap.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); fixed_in 1.12.1/1.13.8.
- privacy_policy_inadequate store Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.
- brand_impersonation store brand_mention.is_impersonation=true (Google mentioned); developer domain kickdrumtech.com, not verified publisher.
- no_developer_name store developer_name is empty; no Offered By identity; +1.0 reputation.
- desktop_capture_permission manifest desktopCapture declared; can record full screen/audio for a Google Docs productivity extension.
- is_featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied (Follows recommended practices).
- maintenance_3_6mo store months_since_update=7; falls in 6-12mo band: +3.5 maintenance.
- obfuscation_clean crx obfuscation_score=0.0, code_findings_raw empty; no malicious code indicators detected.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Standard local data persistence; low risk.
- unlimitedStorage low Allows large local storage; low risk in isolation.
- activeTab low Access to current tab only on user gesture; scoped.
- tabs medium Can read tab URLs and titles; moderate privacy exposure.
- offscreen low Used for off-screen document processing; low standalone risk.
- alarms low Scheduling API; minimal risk.
- identity low OAuth token access; no broad scopes declared.
- desktopCapture medium Can capture screen/audio; significant capability for a Docs annotation tool.
- *://*.highlight-api.gethighlight.com/* medium Scoped host permission to developer's own API domain; acceptable but sends data off-device.
Pillar Scores
Permissions3.60
Reputation5.50
Network2.50
Webstore2.00
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA
b0e989e33600…
Force block
— not fired
Score recovered
no
Elapsed
26.8s