Smart Auto Refresh
fkjngjgmgbfelejhbjblhjkehchifpcj
Risk Score
5.46
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy fetched but admits data collection + third-party sharing without extension-specific scope — scores max privacy risk.
- jquery@3.4.1 bundled with 2 moderate XSS CVEs (CVE-2020-11022, CVE-2020-11023); no CSP amplifies DOM-XSS risk.
- scripting + <all_urls>: can inject arbitrary JS into every page; 22-month-old build leaves this surface unpatched.
- Uninstall and install URL hijacks both trigger (autorefresh.co); collects IP via ip-api.com in js_external_hosts.
- No developer name on record; stale 22 months with high-capability permissions and no content security policy.
Evidence
- privacy_policy_admits_collection_and_sharing_no_scope store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D clause → +10.0 privacy.
- cve_jquery_xss crx jquery@3.4.1 bundled; CVE-2020-11022 + CVE-2020-11023 (moderate); fixed_in 3.5.0 — library below fixed version.
- no_csp_plus_cve_dom_sink crx csp_present=false AND cve_findings non-empty AND dom_sink_innerhtml_userctrl in jquery.js → FIX B +2.0 code quality.
- uninstall_and_install_url_hijack crx Both onInstalled→autorefresh.co/ and setUninstallURL→autorefresh.co/uninstall detected.
- ip_api_external_host crx ip-api.com in js_external_hosts indicates IP geolocation lookup — potential user tracking.
- stale_22_months_high_perm store 22 months since update; scripting+<all_urls> unpatched; falls in 12-24mo band (+6.0 maintenance).
- verified_publisher_featured_cap_applies store Verified+featured discounts capped at -1.0 each (0c): monetization concern via ip-api and stale>18mo.
- no_developer_name store developer_name is empty string; +1.0 reputation penalty applied.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Stores user refresh settings; standard low-risk API.
- unlimitedStorage low Extended quota for settings; low standalone risk.
- tabs medium Access to tab URLs and metadata across all open tabs.
- scripting high Paired with <all_urls> host permission; can inject code into any page.
- <all_urls> (host_permissions) high Grants scripting and content-script access to every site the user visits.
Pillar Scores
Permissions6.50
Reputation3.50
Network4.50
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:10
Listing SHA
0b533c88c544…
Force block
— not fired
Score recovered
no
Elapsed
—