Diigo Web Collector - Capture and Annotate
pnhplgjpclknigjpccbcnmicgcieojbh
Risk Score
5.72
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- 9 moderate CVEs across jquery@1.8.0 and jquery@2.1.0 (both far below fixed version), amplified by DOM-XSS sinks in same codebase.
- eval() and new Function() in content scripts running on <all_urls> create direct code-execution surface on every page visited.
- Privacy policy fetched but scope_extension==false with data_collection==true and third_party_sharing==true — maps to +10.0 under v3.5 rule D.
- Stale extension (24 months since update) with multiple CVEs and MV3; triple-stale fingerprint applies.
- cookies permission combined with <all_urls> host access and scripting on all sites creates broad credential/session-token exfil surface.
Evidence
- cve_jquery_1.8.0 crx 5 moderate CVEs in jquery@1.8.0; fixed_in up to 3.5.0. Library is 13 major versions behind.
- cve_jquery_2.1.0 crx 4 moderate CVEs in jquery@2.1.0; fixed_in up to 3.5.0. Also well below fixed version.
- eval_user_input crx js/content/diigolet.js: devil:function(a){return eval(a)} — direct eval of variable in content script.
- function_constructor crx Multiple new Function() calls in dragresize.js and bundled jquery; code-execution risk.
- dom_sink_innerhtml_userctrl crx 6 files with unguarded innerHTML assignments; CVEs present and no inline CSP on pages.
- privacy_policy_generic store Policy at diigo.com/privacy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
- maintenance_stale_24mo store Last updated June 2024; months_since_update=24. Triple-stale (>24mo + CVEs + MV3-but-old) applies.
- verified_publisher_featured store Verified publisher + Google Featured; discounts capped at -1.0 due to monetization_hits and stale age (v3.5 rule E/0c).
CVE Exposures (9)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2012-6708 | jquery@1.8.0 | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2019-11358 | jquery@1.8.0 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.8.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-7656 | jquery@1.8.0 | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2015-9251 | jquery@1.8.0 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2019-11358 | jquery@2.1.0 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.1.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.1.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.1.0 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- contextMenus low Adds right-click menu items; minimal risk.
- tabs medium Can read tab URLs and titles across all open tabs.
- cookies high Access to cookies; combined with <all_urls> host perm raises exfil risk.
- storage low Local extension storage only; low risk.
- scripting high Programmatic script injection into pages; broad host perm amplifies this.
- pageCapture medium Can capture full page content as MHTML; sensitive data capture possible.
- <all_urls> (host) high Grants access to every site visited; amplifies cookies and scripting risks.
Pillar Scores
Permissions7.50
Reputation2.00
Network3.50
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality7.50
CVE Exposure7.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA
29819e7badaf…
Force block
— not fired
Score recovered
no
Elapsed
41.2s