MailTracker: Email tracker for Gmail
pgbdljpkijehgoacbjpolaomhkoffhnl
Risk Score
4.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- jquery@3.1.1 bundles 3 moderate CVEs (XSS); no CSP amplifies DOM-XSS risk via innerHTML sinks.
- Privacy policy admits data collection and third-party sharing but lacks data retention disclosure.
- new Function() constructor in content-script context enables dynamic code execution risk.
- Uninstall URL redirects to developer-controlled endpoint; install_url_hijack also flagged.
- No developer name listed; no verified publisher badge; email-only identity with self-hosted domain.
Evidence
- cve_findings_raw: 3x moderate jquery@3.1.1 CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) crx jquery@3.1.1 below fixed_in 3.5.0; XSS vulnerabilities in DOM-manipulation lib with no CSP present.
- no content_security_policy + CVEs in jquery (DOM-manipulation lib) manifest csp_present=false with jquery CVEs triggers CVE amplifier ×1.5 on CVE pillar.
- code_findings: function_constructor + 2x dom_sink_innerhtml_userctrl crx new Function() in pageWorld/index.js; innerHTML sinks in userEvents and webcomponents-bundle without CSP.
- privacy policy: data_collection=true, third_party_sharing=true, retention=false store Policy scoped to extension but admits 3rd-party sharing with no retention clause.
- uninstall_url_hijack=true; install_url_hijack=true crx chrome.runtime.setUninstallURL points to app.getmailtracker.com/uninstall; install opens 3rd-party URL.
- developer_name empty; not verified publisher; not featured store No 'Offered by' name in listing; email hello@getmailtracker.com on own domain.
- js_external_hosts includes mailtracker.ngrok.io, polymer.github.io, reactjs.org crx ngrok dev-tunnel host in production build suggests incomplete cleanup; 4 registrable domains.
- is_featured_by_google=true; rating 4.7; no bad_host_hits; no monetization_hits store Featured badge and clean threat-intel partially offset reputation concerns.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11023 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@3.1.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- declarativeNetRequest medium Can block/modify network requests; scoped to mail.google.com host is functional fit.
- storage low Local data persistence; standard for extension state.
- scripting medium Allows script injection into pages; paired with mail.google.com host permission.
- *://mail.google.com/ medium Access to Gmail DOM and email content; expected for email-tracker category.
- *://mailtracker.hunter.io/ medium Access to developer's own tracking dashboard; narrow scope.
Pillar Scores
Permissions3.00
Reputation5.50
Network3.50
Webstore3.50
Maintenance0.00
Privacy2.00
Code Quality4.50
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA
162418cf52f5…
Force block
— not fired
Score recovered
no
Elapsed
35.2s