Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tab Suspender

fiabciakcmgepblmdkmemdbbkilneeeh
Risk Score
5.05
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 100,000
Rating 3.7
Last updated 2026-05-20 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer sergey.drpa@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returns SSL error — policy is unfetchable; treated as no policy (+10 privacy).
  • Three bundled jQuery versions (1.9.1, 1.11.1, 3.3.1) carry 9 moderate CVE instances including XSS; none at fixed_in version.
  • scripting + <all_urls> + content_scripts on all URLs gives full JS injection capability on every site visited.
  • Developer is free-webmail Gmail with no developer name listed, reducing accountability.
  • dynamic <script> creation in jQuery 1.11.1 and multiple innerHTML sinks increase DOM-XSS attack surface.

Evidence

  • privacy_policy_fetch_failed api SSL error fetching https://tab-suspender.com/privacypolicy; classified as fetched=false → +10.0 privacy.
  • cve_moderate_jquery_multiple crx 9 CVE entries across jquery 1.9.1, 1.11.1, 3.3.1 — all moderate, none at fixed_in version.
  • broad_host_scripting manifest host_permissions [*://*/*, <all_urls>] + scripting permission + content_scripts on <all_urls>.
  • free_webmail_no_dev_name store developer_email=sergey.drpa@gmail.com, developer_name empty; free webmail identity.
  • script_src_dynamic crx jquery-1.11.1.min.js creates dynamic <script> elements — script_src_dynamic finding.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discounts applied to reputation.
  • dom_xss_sinks crx innerHTML assignments in mootools, h2c.js, wizard.js; function_constructor in jscolor.min.js.
  • csp_present_mv3 manifest CSP script-src 'self'; object-src 'self' — strict, no unsafe-eval/inline; MV3 no +2 network penalty.

CVE Exposures (9)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2019-11358 jquery@1.11.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.11.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.11.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • tabs medium Access to tab URLs, titles, and navigation — needed for tab suspension but enables browsing surveillance.
  • notifications low Can display notifications; low direct risk.
  • unlimitedStorage low Unlimited local storage; low risk, useful for tab state persistence.
  • contextMenus low Adds right-click menu items; minimal risk.
  • storage low Standard extension storage for settings/state.
  • scripting high Combined with <all_urls> host permission, allows JS injection into any page.
  • favicon low Read favicon URLs; low risk.
  • offscreen low Offscreen document API; limited blast radius.
  • *://*/* high Broad host permission enabling script injection and data access on all sites.
  • <all_urls> high Redundant broad host access; pairs with scripting for full-page access everywhere.
  • content_scripts:<all_urls> high Content scripts run on every page, enabling DOM access across all sites.

Pillar Scores

Permissions6.50
Reputation5.50
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure5.25

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:34
Listing SHA 375240ad42bf…
Force block — not fired
Score recovered no
Elapsed 42.8s