ProWritingAid: Grammar Checker & Paraphrasing Tool
npnbdojkgkbcdfdjlfdmplppdphlhhcf
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's own policy, not scoped to this extension — admits data collection and 3rd-party sharing without extension-level disclosure.
- cookies + broad host access (<all_urls>) enables cross-site session token exfiltration across every site visited.
- dom_sink_innerhtml_userctrl in salesforce-patch.js combined with no content-script CSP creates XSS risk on user pages.
- function_constructor (new Function) usage in polyfills.js and sidepanel.js; sandbox CSP permits unsafe-eval/unsafe-inline.
- No developer name listed in store; no verified-publisher badge reduces accountability.
Evidence
- broad_host_plus_cookies manifest cookies + http://*/* + https://*/* enables cross-origin cookie access on all sites.
- privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's policy, not ProWritingAid's extension policy.
- privacy_scope_extension_false api classification: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- sandbox_csp_unsafe_eval crx sandbox CSP allows unsafe-eval and unsafe-inline on script-src for *.prowritingaid.com.
- function_constructor_findings crx new Function() in polyfills.js and sidepanel.js — dynamic code execution pattern.
- dom_xss_sink crx innerHTML from variable in salesforce-patch.js; csp_present=true but sandbox relaxes restrictions.
- no_developer_name store developer_name is empty; reduces accountability signal.
- featured_by_google store is_featured_by_google=true provides partial trust signal; no verified_publisher badge.
Permissions Breakdown
- tabs medium Can enumerate open tabs and URLs.
- cookies high Combined with broad host access allows reading session cookies across all sites.
- storage low Local extension storage only.
- clipboardRead medium Can silently read clipboard contents at any time.
- clipboardWrite medium Can overwrite clipboard contents.
- scripting high Injects JS into pages; broad host access amplifies this.
- sidePanel low Opens a side panel UI — low standalone risk.
- http://*/* high Broad host access to all HTTP sites; amplifies cookies and scripting.
- https://*/* high Broad host access to all HTTPS sites; amplifies cookies and scripting.
Pillar Scores
Permissions7.00
Reputation4.50
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA
10e2410deef5…
Force block
— not fired
Score recovered
no
Elapsed
25.5s