Twitter Demetricator
abcocamcgfjfdcpfopgpadihhbjbdcem
Risk Score
5.72
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Abandoned: 41 months since last update with known unfixed jQuery CVEs (3x medium XSS).
- Privacy policy is Google's generic policy — does not scope data collection to this extension at all.
- jQuery 3.3.1 bundled without CSP; CVE amplifier applies (jQuery DOM-manipulation lib, no CSP, medium CVEs).
- Developer uses free webmail (gmail) with no dev name listed; brand_mention flags Twitter impersonation.
- dom_sink_innerhtml_userctrl finding in td.user.js combined with no CSP increases XSS exploitability.
Evidence
- stale_extension store Last updated January 2023; 41 months since update. Triple-stale: >24mo + CVEs + MV3 (MV2 bonus N/A but staleness is critical).
- cve_jquery_medium_x3 crx jquery@3.3.1 carries CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all medium); fixed_in 3.5.0 not applied.
- no_csp manifest content_security_policy is null; CVE amplifier ×1.5 applies to CVE pillar (jQuery DOM-manip lib + no CSP).
- generic_privacy_policy store Privacy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
- brand_impersonation store brand_mention.is_impersonation=true for 'twitter'; developer is free webmail with no dev name; featured badge present.
- dom_xss_sink crx dom_sink_innerhtml_userctrl in td.user.js; no CSP and CVEs present → elevated +2.0 code quality penalty.
- free_webmail_no_devname store developer_email=bgrosser@gmail.com, developer_name empty; verified_publisher=true and featured partially offset.
- js_external_hosts crx Extension references bengrosser.com and minus.social; both appear dev-controlled; no bad_host_hits.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Can read tab URLs/titles; moderate privacy exposure.
- storage low Persists local settings; no cross-site exposure.
- content_scripts *://*.twitter.com/* medium Injects JS/CSS into Twitter pages; scoped to single domain.
Pillar Scores
Permissions1.30
Reputation5.50
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA
818b1942fc42…
Force block
— not fired
Score recovered
no
Elapsed
29.0s