AI Grammar Checker & Paraphraser – LanguageTool
oldceeleldhonbafppcapldpdifcinji
Risk Score
4.85
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- eval() used in 4 JS files with no CSP — remote-code-execution risk if any input is attacker-controlled.
- innerHTML sinks in 5 JS files with no CSP amplifies DOM-XSS exposure across all visited pages.
- Privacy policy fetched but scope_extension==false and admits data collection + third-party sharing → scores maximum privacy risk.
- Content script injected on <all_urls> gives broad reach over all browsing; text sent to multiple languagetool API endpoints.
- No developer display name in listing reduces accountability despite known email domain.
Evidence
- eval_user_input_multi_file crx eval() of variable found in background.js, changelog.js, feedbackForm.js, trial.js — no CSP to mitigate.
- dom_sink_innerhtml_no_csp crx innerHTML sinks in content.js, options.js, popup.js, toolbox.js, validator.js with csp_present==false.
- privacy_policy_generic_with_3p_sharing api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0.
- content_script_all_urls manifest <all_urls> in content_scripts_matches; extension processes text on every page visited.
- uninstall_url_hijack store uninstall_url_hijack=true; extension registers an uninstall URL redirect.
- no_csp_mv3 manifest content_security_policy is null; amplifies eval and innerHTML findings.
- ai_extension_page_content store AI grammar/paraphrase extension processes page text and sends to languagetool API endpoints.
- featured_by_google store is_featured_by_google=true; applies featured discount to reputation pillar.
Permissions Breakdown
- activeTab medium Access to current tab on user action; low standalone risk but enables content injection with scripting.
- storage low Stores user preferences/settings locally.
- contextMenus low Adds right-click menu items; low risk.
- scripting medium Can inject JS/CSS into pages; medium risk, paired with <all_urls> content_script match.
- alarms low Background scheduling; low risk.
- <all_urls> (content_scripts_matches) high Content script injected on all URLs — broad reach over every site the user visits.
Pillar Scores
Permissions4.80
Reputation4.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality7.00
CVE Exposure0.00
Scoring History
| sssiedn3eaa8446dp727562726963xsx | 5.17 | Medium | review | 2026-09-06 |
| %76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%51%44%65%68%28%39%38%30%30%34%29%22 | 4.41 | Medium | review | 2026-08-05 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 4.85 | Medium | review | 2026-08-05 |
| v3.6'"()&%<zzz><ScRiPt >QDeh(9078)</ScRiPt> | 5.07 | Medium | review | 2026-08-05 |
| sssieddrubricxsx | 4.57 | Medium | review | 2026-08-04 |
| v3.6 | 4.85 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA
bd0cd1969d5c…
Force block
— not fired
Score recovered
no
Elapsed
27.7s