Template Search
cnkcgoiimpncbonlilkekbigfhchcbgb
Risk Score
6.49
Risk Level:
High
Recommendation:
🟠 HIGH RISK — review
Top Risks
- Default search engine hijacked to developer-controlled endpoint (templatesearch-svc.org); uninstall URL also hijacked.
- Privacy policy admits data collection + third-party sharing but has no extension-specific scope — maximum privacy score.
- Three moderate CVEs in bundled jquery@3.3.1 (below fixed_in 3.5.0); no CSP amplifies XSS exploitability.
- Free-webmail developer (gmail) with no verified publisher badge and a 2.3 rating signals low-accountability operator.
- Extension stale at 18 months with known-vulnerable jQuery; no code update to patch CVEs.
Evidence
- search_provider_override manifest chrome_settings_overrides sets default search to services.templatesearch-svc.org; is_default=true.
- uninstall_url_hijack crx uninstall_url_hijack==true; extension registers uninstall URL redirect to 3rd-party endpoint.
- privacy_policy_generic_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule → +10.0.
- jquery_cve_trio crx jquery@3.3.1 has 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
- no_csp_amplifies_cve manifest csp_present=false; jquery@<3.5 + no CSP triggers v2e +2.0 Code Quality penalty.
- free_webmail_developer store Developer email templatesearchnow@gmail.com; no verified publisher; no featured badge.
- low_rating store Rating 2.3; extension has 50K installs but poor user satisfaction signal.
- stale_18mo store Last updated Feb 2025; months_since_update=18; CVEs unpatched for full stale window.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- cookies high Allows reading/writing cookies across permitted origins; combined with search override = tracking risk.
- storage low Local extension storage; low standalone risk.
- tabs medium Can read tab URLs and titles; supports user surveillance when combined with other permissions.
- search medium Allows overriding the browser search engine; monetization risk.
- declarativeNetRequest medium Can redirect or block network requests; combined with search override elevates risk.
- chrome_settings_overrides.search_provider high Sets default search engine to developer-controlled endpoint; classic search-hijack vector.
- host_permissions: *://*.templatesearch-svc.org/* medium Scoped to developer domain but enables cookie and request access on all subdomain traffic.
Pillar Scores
Permissions7.00
Reputation7.50
Network2.00
Webstore7.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-08-31 10:13
Listing SHA
b382c1e5d3bc…
Force block
— not fired
Score recovered
no
Elapsed
—