MultiCopy Clipboard, Copy & Paste
fahoojlhneomlloahghepkcegggkpahh
Risk Score
3.59
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- jquery@3.2.0 bundles 3 medium CVEs (XSS); no CSP amplifies risk per v2 calibration.
- content_scripts on <all_urls> means extension code runs on every page visited.
- Privacy policy scoped but lacks data retention disclosure and is silent on third-party sharing.
- install_url_hijack flag set; onInstalled may open third-party URL.
- Rating 3.3 with 10K installs and no verified publisher badge reduces trust.
Evidence
- CVE_findings crx 3 medium CVEs in jquery@3.2.0 (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
- no_csp manifest content_security_policy is null; MV3 default applies but jquery CVEs gain XSS amplification risk.
- content_scripts_all_urls manifest content_scripts_matches=['<all_urls>']; broad page access for a clipboard tool.
- install_url_hijack crx install_url_hijack=true; target is null but flag indicates onInstalled opens external URL.
- privacy_policy_gaps store Policy fetched, scoped, data_collection=true but retention=false and third_party_silence=true.
- rating_below_average store Rating 3.3; no verified_publisher badge; not sufficient negative reviews flagged.
- js_external_hosts crx 7 external hosts referenced (bunq.me, github.com, paulirish.com, etc.); 2 countries (IN, US).
- featured_by_google store is_featured_by_google=true provides partial trust signal offsetting some reputation risk.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.0 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.0 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- activeTab low Scoped to current tab on user gesture; limited blast radius.
- storage low Stores clipboard items locally; no cross-origin access implied.
- contextMenus low Adds right-click menu items; benign for clipboard utility.
- notifications low Desktop notifications only; no data exfil vector.
- scripting medium Can inject scripts into pages; combined with content_scripts <all_urls> raises reach.
- content_scripts:<all_urls> medium Runs on every page; exposes clipboard reads across all sites user visits.
Pillar Scores
Permissions3.30
Reputation5.50
Network1.50
Webstore3.50
Maintenance1.50
Privacy2.00
Code Quality3.00
CVE Exposure4.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA
013fbc239ea1…
Force block
— not fired
Score recovered
no
Elapsed
25.6s