Popup Blocker for Google Chrome™
ddmhlmdockeihjdpbkcnnfnlcgjhccgk
Risk Score
6.83
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Google™ brand impersonation by gmail.com developer with no verified business — clear reputation risk.
- Extension abandoned 53 months ago with 3 unpatched jQuery CVEs (XSS) and no CSP; CVE×1.5 amplifier applies.
- content_scripts on <all_urls> injects vulnerable jQuery into every page; eval_user_input + innerHTML sink present.
- Privacy policy is Google's generic account policy — scope_extension=false, admits data collection & 3rd-party sharing.
- Uninstall URL hijack and install URL hijack flagged; description promises ad-blocking but lacks webRequest/DNR.
Evidence
- brand_impersonation store Title contains 'Google Chrome™' trademark; brand_mention.is_impersonation=true, confirmed_owner=false, dev=gmail.com.
- stale_extension store Last updated January 2022; 53 months since update triggers maintenance score 10.0.
- jquery_cve_triple crx jquery@3.1.1 carries 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP amplifies risk ×1.5.
- generic_privacy_policy store Privacy policy is myaccount.google.com — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
- uninstall_install_hijack crx Both install_url_hijack and uninstall_url_hijack are true; targets null but pattern is monetization shell indicator.
- content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] injects into every page despite no host_permissions declared.
- description_mismatch store Promises ad/popup-blocking but lacks declarativeNetRequest or webRequest permission.
- free_webmail_no_dev_name store developer_email=keyaan.travis2021@gmail.com, developer_name empty; no business identity verifiable.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.1.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- activeTab low Grants access only to active tab on user interaction; limited blast radius.
- storage low Persists local settings; no cross-origin data risk on its own.
- contextMenus low Adds right-click menu items; low direct risk.
- content_scripts:<all_urls> high Injects JS into every page; high reach despite narrow declared permissions.
Pillar Scores
Permissions3.30
Reputation7.50
Network2.00
Webstore8.50
Maintenance10.00
Privacy10.00
Code Quality5.50
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA
c66290189d31…
Force block
— not fired
Score recovered
no
Elapsed
30.5s