PerfecTab
eflcledgcbkinocjidjjcakgmeidoann
Risk Score
5.56
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Extension is 28 months stale — zombie risk with 40K users on new tab surface.
- jquery@1.11.2 carries 3 moderate XSS CVEs; no CSP amplifies DOM-XSS risk.
- 12 external JS hosts including under-cover.info and ressourceapp.com — opaque/suspicious endpoints.
- New-tab override on 40K installs; every new tab is a high-reach trust boundary.
- Free-webmail developer email (outlook.com) with no verified publisher badge.
Evidence
- newtab_override manifest chrome_url_overrides.newtab set — intercepts every new tab for 40K users.
- stale_extension store 28 months since last update; qualifies for zombie-booster (>24mo + 10K+ installs).
- jquery_cve crx jquery@1.11.2 with CVE-2019-11358, CVE-2020-11023, CVE-2015-9251 (3x moderate XSS); fixed in 3.5.0.
- no_csp_plus_cve crx csp_present==false AND 3 moderate CVEs in jquery; dom_sink_innerhtml_userctrl triggers elevated score.
- suspicious_external_hosts crx under-cover.info and www.ressourceapp.com in js_external_hosts — non-obvious, opaque domains.
- script_src_dynamic crx Dynamic <script src=> creation in jquery.min.js — remote code loading surface.
- free_webmail_dev store Developer email myperfecttab@outlook.com; no verified publisher badge.
- search_engine_count_2 crx NewTab contacts 2 search engines (google.com, yahoo.com) — minor monetization signal.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.11.2 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.11.2 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.11.2 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- geolocation medium Exposes physical location; plausible for weather widget but privacy risk if misused.
- storage low Local data persistence; standard for NewTab customization.
- topSites medium Exposes user browsing history summary; standard for NewTab but leakable.
- chrome_url_overrides.newtab medium Replaces every new tab page — high reach, intercepts user navigation intent.
Pillar Scores
Permissions3.00
Reputation6.50
Network5.50
Webstore5.50
Maintenance8.50
Privacy0.00
Code Quality5.50
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-09-01 15:47
Listing SHA
1478ba15e466…
Force block
— not fired
Score recovered
no
Elapsed
—