Tab to Window/Popup - Keyboard Shortcut
adbkphmimfcaeonicpmamfddbbnphikh
Risk Score
4.97
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- 8 moderate CVEs in bundled jquery@1.9.1 and jquery-ui@1.10.1 (XSS); no CSP amplifies risk (×1.5 CVE multiplier applied).
- Privacy policy is Google's generic account policy — scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
- No CSP on MV3 extension; dynamic script creation in vulnerable jquery version with no mitigation.
- Extension stale 22 months; jquery/jquery-ui libs far behind fixed versions with no update.
- install_url_hijack flag set; onInstalled opens external URL (target null but flag true).
Evidence
- cve_moderate_x8 crx 8 moderate CVEs in jquery@1.9.1 and jquery-ui@1.10.1; all below fixed_in versions; no CSP → ×1.5 amplifier.
- no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit hardening; amplifies CVE risk.
- generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_extension store Last updated August 2024; 22 months since update; jquery libs severely outdated.
- install_url_hijack crx install_url_hijack=true; onInstalled opens external URL; target is null so destination unverified.
- dynamic_script_creation crx script_src_dynamic found in jquery-1.9.1.min.js; combined with CVEs raises code quality risk.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reputation floor 2.0 applied; discounts capped per 0c (stale>18mo).
- js_external_hosts crx Extension references acarabott.github.io and jqueryui.com as external JS hosts; 2 distinct domains.
CVE Exposures (8)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-41182 | jquery-ui@1.10.1 | moderate | 1.13.0 | XSS in the `altField` option of the Datepicker widget in jquery-ui |
| CVE-2021-41184 | jquery-ui@1.10.1 | moderate | 1.13.0 | XSS in the `of` option of the `.position()` util in jquery-ui |
| CVE-2022-31160 | jquery-ui@1.10.1 | moderate | 1.13.2 | jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in |
| CVE-2016-7103 | jquery-ui@1.10.1 | moderate | 1.12.0 | jQuery-UI vulnerable to Cross-site Scripting in dialog closeText |
| CVE-2021-41183 | jquery-ui@1.10.1 | moderate | 1.13.0 | XSS in `*Text` options of the Datepicker widget in jquery-ui |
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Local preference storage; standard low-risk permission.
- system.display low Read display geometry to place new windows; narrow, non-sensitive.
- contextMenus low Adds right-click menu entry; no data access.
Pillar Scores
Permissions0.90
Reputation2.00
Network2.00
Webstore3.00
Maintenance6.00
Privacy10.00
Code Quality6.00
CVE Exposure7.50
Scoring History
| fsssiedxa sssiedx | 4.17 | Medium | review | 2026-08-20 |
| sssieddrubricxsx | 4.49 | Medium | review | 2026-08-20 |
| v3.6 | 4.97 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA
e13cbd46dd6e…
Force block
— not fired
Score recovered
no
Elapsed
34.2s