Sapling Grammar Checker and Writing Assistant
pjpgohokimaldkikgejifibjdpbopfdc
Risk Score
5.26
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); fix available at 1.12.1.
- High CVE in underscore@1.8.3 (CVE-2026-27601: DoS via recursion); fix available at 1.13.8.
- Privacy policy fetched but lacks extension scope, discloses third-party data sharing without restricting to this extension.
- <all_urls> host permission with scripting enables content injection across every website the user visits.
- AI grammar/writing assistant reads page content and clipboard — high sensitivity data processed and sent to sapling.ai.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); not updated to fixed_in 1.12.1.
- high_cve_bundled_lib crx underscore@1.8.3 has CVE-2026-27601 (high, DoS); not updated to fixed_in 1.13.8.
- privacy_policy_generic store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (D rule).
- broad_host_access manifest <all_urls> host_permission combined with scripting and content_scripts enables full page access.
- function_constructor_in_bundles crx new Function() found in main-bundle.js and background-bundle.js; low-risk polyfill pattern but noted.
- verified_publisher_featured store Verified publisher + is_featured_by_google; reputation discounts applied but capped per 0c (CVEs present).
- developer_name_missing store developer_name field is empty string; dev identity via email only (team@sapling.ai).
- csp_present_mv3 manifest CSP script-src 'self'; object-src 'self'; no unsafe-eval/inline. MV3 strict defaults apply.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- activeTab low Scoped to user-invoked action only.
- alarms low Background scheduling, low risk.
- clipboardRead medium Can read clipboard contents — potential data exfil vector.
- clipboardWrite low Writes to clipboard; limited risk.
- identity medium OAuth token access; can identify user account.
- identity.email medium Exposes user email address via OAuth.
- offscreen low Offscreen document; low risk alone.
- scripting medium Can inject scripts into pages; combined with <all_urls> raises risk.
- storage low Local extension storage only.
- tabs medium Can read tab URLs and metadata across browser.
- webNavigation medium Monitors navigation events across sites.
- <all_urls> high Broad host access — content scripts and scripting API apply to every site.
Pillar Scores
Permissions5.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA
194675af06ce…
Force block
— not fired
Score recovered
no
Elapsed
29.1s