Ref Schedule Sync
pgdajjngmjfhnoghgoddckkikijklaib
Risk Score
5.88
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Abandoned: 56 months since last update, no maintenance for nearly 5 years.
- Privacy policy is Google's own policy, not scoped to this extension — admits data collection and 3rd-party sharing.
- Bundled jquery@3.3.1 has 3 moderate CVEs (XSS); unfixed since extension is stale.
- Developer uses free Gmail account with no verified business identity; brand_mention flags Google impersonation.
- Generic policy admits data_collection and third_party_sharing without extension-specific scope.
Evidence
- stale_extension store Last updated December 2021; 56 months elapsed — well past 36-month zombie threshold.
- privacy_policy_generic store Privacy URL points to Google's global policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- cve_moderate_jquery crx jquery@3.3.1 has 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
- free_webmail_developer store Developer email matthew.rosenfeld22@gmail.com; no verified publisher, no business domain.
- brand_impersonation store brand_mention.is_impersonation=true (Google mentioned); developer domain is gmail.com, confirmed_owner=false.
- very_low_installs store Only 4 installs; limited blast radius but tail-attack-surface concern absent (no high-tier perms).
- content_scripts_narrow manifest Content scripts scoped to two specific referee scheduling domains; matches stated function.
- js_external_hosts crx External JS hosts limited to accounts.google.com and www.googleapis.com; consistent with Google Calendar OAuth.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Stores local extension data; low risk.
- tabs medium Can read tab URLs/titles; medium risk without broad host access.
- identity medium OAuth token access; used here for Google Calendar API.
- content_scripts: horizonwebref.com + arbitersports.com low Narrowly scoped to two referee scheduling sites; matches stated function.
Pillar Scores
Permissions2.00
Reputation7.50
Network1.00
Webstore3.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:18
Listing SHA
84438af2e338…
Force block
— not fired
Score recovered
no
Elapsed
—