Tab Suspender
fiabciakcmgepblmdkmemdbbkilneeeh
Risk Score
5.05
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL returns SSL error — policy is unfetchable; treated as no policy (+10 privacy).
- Three bundled jQuery versions (1.9.1, 1.11.1, 3.3.1) carry 9 moderate CVE instances including XSS; none at fixed_in version.
- scripting + <all_urls> + content_scripts on all URLs gives full JS injection capability on every site visited.
- Developer is free-webmail Gmail with no developer name listed, reducing accountability.
- dynamic <script> creation in jQuery 1.11.1 and multiple innerHTML sinks increase DOM-XSS attack surface.
Evidence
- privacy_policy_fetch_failed api SSL error fetching https://tab-suspender.com/privacypolicy; classified as fetched=false → +10.0 privacy.
- cve_moderate_jquery_multiple crx 9 CVE entries across jquery 1.9.1, 1.11.1, 3.3.1 — all moderate, none at fixed_in version.
- broad_host_scripting manifest host_permissions [*://*/*, <all_urls>] + scripting permission + content_scripts on <all_urls>.
- free_webmail_no_dev_name store developer_email=sergey.drpa@gmail.com, developer_name empty; free webmail identity.
- script_src_dynamic crx jquery-1.11.1.min.js creates dynamic <script> elements — script_src_dynamic finding.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discounts applied to reputation.
- dom_xss_sinks crx innerHTML assignments in mootools, h2c.js, wizard.js; function_constructor in jscolor.min.js.
- csp_present_mv3 manifest CSP script-src 'self'; object-src 'self' — strict, no unsafe-eval/inline; MV3 no +2 network penalty.
CVE Exposures (9)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2019-11358 | jquery@1.11.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.11.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.11.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- tabs medium Access to tab URLs, titles, and navigation — needed for tab suspension but enables browsing surveillance.
- notifications low Can display notifications; low direct risk.
- unlimitedStorage low Unlimited local storage; low risk, useful for tab state persistence.
- contextMenus low Adds right-click menu items; minimal risk.
- storage low Standard extension storage for settings/state.
- scripting high Combined with <all_urls> host permission, allows JS injection into any page.
- favicon low Read favicon URLs; low risk.
- offscreen low Offscreen document API; limited blast radius.
- *://*/* high Broad host permission enabling script injection and data access on all sites.
- <all_urls> high Redundant broad host access; pairs with scripting for full-page access everywhere.
- content_scripts:<all_urls> high Content scripts run on every page, enabling DOM access across all sites.
Pillar Scores
Permissions6.50
Reputation5.50
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure5.25
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA
375240ad42bf…
Force block
— not fired
Score recovered
no
Elapsed
42.8s