SpeedUp: Netflix, Prime videos
pldkddbkbcedophgedaeofceedjcaehl
Risk Score
6.06
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Brand impersonation: names Netflix, Amazon, YouTube, Twitch, Reddit without ownership; gmail dev with no verified business.
- Privacy policy is Google's generic policy — scope_extension=false, admits data_collection+third_party_sharing; effectively no extension-specific policy.
- jquery@3.4.1 with two XSS CVEs (CVE-2020-11022, CVE-2020-11023) bundled; no CSP amplifies DOM-XSS risk.
- <all_urls> host_permissions + content_scripts on every site grants persistent read/write access across all user browsing.
- Developer uses numbered-alias gmail (businessinsider11@gmail.com) with no verified business domain or publisher badge.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands: amazon, youtube, reddit, netflix, twitch; dev domain gmail.com, not verified.
- free_webmail_dev_numbered_alias store Developer email businessinsider11@gmail.com — numbered alias free webmail, no business website, not verified publisher.
- privacy_policy_generic api Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- cve_jquery_xss crx jquery@3.4.1 bundled; CVE-2020-11022 + CVE-2020-11023 (moderate XSS); fixed_in 3.5.0. No CSP present.
- dom_sink_innerhtml crx js/popup.js: innerHTML assigned from variable speed_display; no CSP and CVEs present → elevated DOM-XSS risk.
- host_permissions_all_urls manifest <all_urls> in host_permissions + content_scripts_matches; scripting permission enables injection into every site.
- no_csp manifest content_security_policy is null (MV3, so no MV2 penalty, but amplifies CVE/DOM-sink risk).
- stale_20mo_with_cves store months_since_update=20; CVEs present and unfixed; no update addressing known vulnerabilities.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Stores speed preferences locally; minimal risk.
- scripting medium Allows programmatic script injection into pages.
- <all_urls> (host_permissions) high Full read/write access to every page the user visits.
- <all_urls> (content_scripts) high Content scripts auto-inject into every origin, broad attack surface.
Pillar Scores
Permissions5.50
Reputation8.00
Network2.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure3.00
Scoring History
| fsssiedxnfffd8138za'nfffd8138zsssiedx | 5.44 | Medium | review | 2026-08-27 |
| sssiedn8fa879f9dp727562726963xsx | 5.41 | Medium | review | 2026-08-27 |
| v3.6 | 6.06 | High | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA
6c0e23a8f610…
Force block
— not fired
Score recovered
no
Elapsed
27.1s