Annotate Web
njfokngnhkjhcdnepoaleidpgagmcjbj
Risk Score
4.24
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic policy — scope_extension=false, data_collection=true, third_party_sharing=true; admits broad data sharing without scoping to this extension.
- Uninstall URL hijack: chrome.runtime.setUninstallURL to uninstall.annotateweb.org — classic monetization/tracking signal.
- Install URL hijack: onInstalled opens welcome.annotateweb.org — third-party redirect on install.
- No developer name listed; gmail.com developer email with no verified business identity.
- No CSP present (MV3 strict default applies, but DOM-XSS sink found in draw.js with innerHTML from variable).
Evidence
- uninstall_url_hijack crx chrome.runtime.setUninstallURL points to uninstall.annotateweb.org — third-party uninstall tracking.
- install_url_hijack crx onInstalled opens welcome.annotateweb.org — third-party redirect on install.
- privacy_policy_generic store Policy is Google's own account policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true.
- free_webmail_dev_no_name store Developer email a.lenko.ext@gmail.com; developer_name empty; no verified business identity.
- dom_xss_sink crx draw.js: innerHTML assigned from variable (dom_sink_innerhtml_userctrl); no CSP to mitigate.
- no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
- verified_publisher store verified_publisher=true; months_since_update=5; no monetization/CVE hits — full -3.0 discount applies.
- no_bad_hosts_no_cves api bad_host_hits=[], affiliate_hits=[], cve_findings_raw=[], obfuscation_score=0.0.
Permissions Breakdown
- activeTab low Scoped to user-initiated action on current tab only.
- scripting medium Can inject scripts; combined with activeTab limits scope but still capable.
- notifications low Can display browser notifications; limited harm potential.
- storage low Local data persistence only; low direct risk.
Pillar Scores
Permissions2.30
Reputation6.50
Network2.00
Webstore5.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:58
Listing SHA
22bfc848cf27…
Force block
— not fired
Score recovered
no
Elapsed
21.4s