Url Shortener for Google Chrome™
aacgdipdhmilcpcpbdcloifondogabco
Risk Score
6.24
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Google brand impersonation: title claims '™' affiliation but developer is unverified gmail user with no dev name.
- Privacy policy fetch failed (ConnectionError) and URL domain is unrelated Facebook tool — treated as no valid policy.
- Install/uninstall URL hijack flags set; both targets unresolvable but pattern is consistent with monetization shell.
- jquery@2.2.4 bundles 4 moderate CVEs (XSS); no CSP present — v2 ×1.5 CVE amplifier applies.
- 32 months since last update with 200k installs — abandoned high-reach extension with known-vulnerable library.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; brands=['google']; developer_email=gmail.com; confirmed_owner=false.
- privacy_policy_unreachable api Privacy policy fetch_error:ConnectionError; URL domain is unrelated Facebook tool. Scored as fetched=false → +10.0.
- install_uninstall_hijack crx install_url_hijack=true AND uninstall_url_hijack=true; targets null but flags present per manifest scan.
- cve_vulnerable_jquery crx jquery@2.2.4: CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251 — all moderate XSS; fixed_in 3.5.0.
- no_csp_with_cves crx csp_present=false + 4 moderate CVEs in jquery (DOM-manipulation lib) → CVE pillar ×1.5 amplifier applied.
- stale_abandoned store 32 months since update; 200k installs; MV3 but jquery not updated. +8.5 maintenance + zombie booster +1.0 capped at 10.
- free_webmail_no_devname store developer_email=gmail.com; developer_name empty; no business website → reputation floor ≥7.5 triggered.
- dom_sink_innerhtml crx code_findings_raw: dom_sink_innerhtml_userctrl in data/libs/Localize.js; no CSP present → +2.0 (FIX B).
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.2.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.2.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.2.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.2.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- activeTab low Scoped to user-initiated action on current tab only.
- storage low Local storage for settings; no cross-site capability.
- host:https://chart.googleapis.com/* low Narrow Google API host for URL shortening/QR generation.
- host:https://tinyurl.com/* low Narrow TinyURL host for URL shortening service.
Pillar Scores
Permissions0.60
Reputation8.00
Network2.00
Webstore7.00
Maintenance8.50
Privacy10.00
Code Quality2.50
CVE Exposure4.50
Scoring History
| sssiedn3f612372dp727562726963xsx | 6.39 | High | block | 2026-09-08 |
| fsssiedxn14d9af02za'n14d9af02zsssiedx | 6.52 | High | block | 2026-09-06 |
| sssiedn95da1c86dp727562726963xsx | 6.38 | High | block | 2026-09-06 |
| v3.6 | 6.24 | High | block | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:14
Listing SHA
afd000eac20b…
Force block
— not fired
Score recovered
no
Elapsed
34.6s