Redmine Markdown Preview & Converter
pjljjnfmpmdpodlcpkccddidfadmgfep
Risk Score
4.07
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Generic Google privacy policy (scope_extension=false, admits data_collection+third_party_sharing) — worst privacy classification.
- Developer identity is a numbered Gmail alias (bysky5.44.32.164@gmail.com) with no verified business presence.
- brand_mention flags github impersonation (confirmed_owner=false); extension loads assets-cdn.github.com.
- DOM-XSS sink (innerHTML on user-controlled HTML) with no CSP — exploitation surface for malicious Markdown input.
- No install count or rating data; unknown blast radius and no community trust signals.
Evidence
- privacy_policy_generic_google store Policy is Google's own account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
- developer_free_webmail_alias manifest Dev email bysky5.44.32.164@gmail.com — numbered alias, no business domain, no verified publisher.
- brand_impersonation_github store brand_mention.is_impersonation=true for 'github'; confirmed_owner=false. Contacts assets-cdn.github.com.
- dom_xss_no_csp crx innerHTML sink in markdown-engine.js with csp_present=false → dom_sink_innerhtml_userctrl elevated to +2.0.
- no_install_count store installs field empty; reach unknown but no popularity signals.
- js_external_hosts crx External hosts: assets-cdn.github.com, github.com — consistent with Markdown rendering; single country (IN).
- reputation_numbered_alias store Free-webmail + numbered alias + no business website → reputation floor rules apply.
- mv3_no_csp manifest MV3 extension; no explicit CSP declared. MV3 strict default applies — no +2.0 network penalty.
Permissions Breakdown
- activeTab low Scoped to current tab only on user action; minimal blast radius.
- scripting medium Allows programmatic script injection into pages; elevated risk without host_permissions.
Pillar Scores
Permissions1.30
Reputation8.00
Network0.00
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA
5dc9b71bc1fc…
Force block
— not fired
Score recovered
no
Elapsed
22.5s