Read fast - Speed Reading Extension
pnffahcjemjliibgcafjpklgmbeknldi
Risk Score
5.63
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Abandoned: not updated in 51 months — high risk of unpatched vulnerabilities and supply-chain takeover.
- 8 moderate CVEs in bundled jquery@1.9.0 and jquery-ui@1.10.0, both far below fixed versions.
- Privacy policy is Google's generic account policy — not scoped to this extension at all.
- Content script injected on <all_urls> gives DOM access across every site the user visits.
- Developer uses free Gmail address with no verified business identity or domain.
Evidence
- months_since_update=51 store Last updated March 2022; 51 months stale — maintenance pillar maxed at 10.0.
- cve_moderate_x8 crx 8 moderate CVEs across jquery@1.9.0 and jquery-ui@1.10.0; none fixed in bundled versions.
- privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, admits data_collection+third_party_sharing.
- content_scripts_all_urls manifest content_scripts match <all_urls>, http://*/*, https://*/*ーbroad DOM reach on every page.
- free_webmail_dev store Developer email mj.code.assist@gmail.com; no verified publisher, no business domain.
- script_src_dynamic crx Dynamic script element creation in bundled jquery-1.9.0.min.js.
- js_external_hosts crx References to bugs.jquery.com, jqueryui.com, www.mediacollege.com in extension JS.
- triple_stale_fingerprint crx >24mo stale + CVEs present + MV3 (no v2 CSP penalty applied); stale+CVE combo amplifies risk.
CVE Exposures (8)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-41182 | jquery-ui@1.10.0 | moderate | 1.13.0 | XSS in the `altField` option of the Datepicker widget in jquery-ui |
| CVE-2021-41184 | jquery-ui@1.10.0 | moderate | 1.13.0 | XSS in the `of` option of the `.position()` util in jquery-ui |
| CVE-2022-31160 | jquery-ui@1.10.0 | moderate | 1.13.2 | jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in |
| CVE-2016-7103 | jquery-ui@1.10.0 | moderate | 1.12.0 | jQuery-UI vulnerable to Cross-site Scripting in dialog closeText |
| CVE-2021-41183 | jquery-ui@1.10.0 | moderate | 1.13.0 | XSS in `*Text` options of the Datepicker widget in jquery-ui |
| CVE-2019-11358 | jquery@1.9.0 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.0 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- content_scripts:<all_urls> high Content script injected into every page — broad read/DOM access across all sites.
Pillar Scores
Permissions2.00
Reputation6.50
Network0.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality3.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA
b0fb80f0efa6…
Force block
— not fired
Score recovered
no
Elapsed
32.0s