Sidebarr - Bookmarks, Apps and more
afdfpkhbdpioonfeknablodaejkklbdn
Risk Score
6.58
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Uninstall and install URL hijack both set — traffic-monetization pattern, no declared targets.
- Privacy policy admits data collection + third-party sharing but not scoped to this extension → scores +10.
- No CSP + multiple innerHTML sinks across 5 bundle files + function_constructor elevates DOM-XSS risk.
- Free-webmail developer (gmail), no developer name, broad <all_urls> host access — low accountability.
- 7 external JS hosts including chat.sidebarr.net and CDNs loaded from extension with no CSP guard.
Evidence
- uninstall_url_hijack + install_url_hijack crx Both hijack flags set; targets null but pattern matches low-effort traffic-monetization (+3+2 Webstore).
- privacy_policy scoped=false, data_collection=true, third_party_sharing=true api Policy admits collection+sharing without scoping to extension → Privacy pillar +10 (v3.5 rule D).
- free-webmail dev, no developer name store romsiubsass@gmail.com, developer_name empty → Reputation +1.5+1.0 = floor near 7.
- no CSP (csp_present=false, MV3) crx MV3 has strict-default but explicit null CSP; no MV2 +2 penalty; but worsens innerHTML sink severity.
- dom_sink_innerhtml_userctrl × 5 files + no CSP crx csp_present==false triggers +2.0 per FIX B for each; consolidated to code_quality +2.5 signal.
- function_constructor in contentScript.bundle.js crx new Function() constructor → +2.5 Code Quality.
- 7 external JS hosts including sidebarr.org, chat.sidebarr.net crx >3 distinct registrable domains → Network +1.5.
- verified_publisher=true, free-webmail email, no domain resolves check store Verified publisher discount capped at -1.0 (developer_domain_info null, cannot confirm domain).
Permissions Breakdown
- storage low Local data persistence only.
- bookmarks medium Read/write all browser bookmarks.
- scripting medium Can inject scripts into pages; elevated with <all_urls>.
- unlimitedStorage low No direct data exfil risk, just quota bypass.
- favicon low Read site favicons only.
- declarativeNetRequest medium Can intercept/block network requests.
- tabs medium Can read tab URLs and metadata across all tabs.
- alarms low Scheduling only, no direct data access.
- <all_urls> (host) high Content scripts and scripting API reach every site the user visits.
Pillar Scores
Permissions7.00
Reputation7.00
Network6.50
Webstore8.50
Maintenance3.50
Privacy10.00
Code Quality5.50
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:47
Listing SHA
42381d12943e…
Force block
— not fired
Score recovered
no
Elapsed
—