Calendar Selector for Google Calendar
nmliklikilkjommabacojbijjimlgjck
Risk Score
4.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- jQuery 2.0.0 bundled with 4 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); no CSP to mitigate.
- Brand-mention impersonation flag: extension name/listing references 'Google' but developer is not Google and is not verified.
- Privacy policy linked is Google's global account policy, not a developer-authored policy for this extension.
- No CSP declared (MV3 default applies but no explicit hardening); innerHTML DOM-XSS sink in bundled jQuery.
Evidence
- privacy_policy_generic_google store Privacy policy URL points to myaccount.google.com — Google's own policy, not the developer's. scope_extension=false, data_collection=true, third_party_sharing=true.
- cve_jquery_moderate_x4 crx jquery@2.0.0 bundles CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251 (all moderate XSS). fixed_in 3.5.0.
- brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['google']; developer is Bluenexa LLC, not verified publisher, not Google.
- dom_sink_innerhtml crx lib/jquery/jquery.js: innerHTML assignment from variable — DOM-XSS sink; no CSP present to mitigate.
- no_csp_mv3 manifest content_security_policy is null; MV3 default applies but no explicit CSP hardening declared.
- host_permissions_narrow manifest host_permissions limited to https://calendar.google.com/* — narrow and matches stated function.
- featured_by_google store is_featured_by_google=true; provides partial reputation credit but does not resolve impersonation or privacy policy issues.
- operator_cluster_clean api sibling_count=0; no related suspicious extensions under same fingerprint. Domain bluenexa.com resolves, not throwaway.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.0.0 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.0.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.0.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.0.0 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Saves/restores calendar group settings locally; expected for this function.
- https://calendar.google.com/* medium Content script scoped to single Google Calendar domain; narrow but sensitive.
Pillar Scores
Permissions1.30
Reputation5.00
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA
358a0c739735…
Force block
— not fired
Score recovered
no
Elapsed
27.0s