Url Shortener
godoifjoiadanijplaghmhgfeffnblib
Risk Score
3.67
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- jquery@3.2.1 carries 3 medium XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP present amplifies risk.
- No CSP on MV3 extension with 11 external JS hosts; scripting permission can inject into active tab.
- 11 distinct external host endpoints (bitly, cutt.ly, is.gd, tny.im, etc.); large outbound surface for a URL shortener.
- Privacy policy discloses third-party data sharing but lacks retention details; scope is extension-specific but incomplete.
- Developer name field empty; identity relies solely on domain and verified-publisher badge.
Evidence
- jquery_cve_triple crx jquery@3.2.1 bundled; 3 medium CVEs unfixed (fixed_in 3.5.0); no CSP to mitigate XSS exploitation.
- no_csp manifest content_security_policy is null on MV3; v2 calibration adds +2.0 Network for MV2 but MV3 has strict default — no extra penalty applied.
- eleven_external_hosts crx js_external_hosts has 11 distinct registrable domains; >3 threshold triggers +1.5 network penalty.
- verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; reputation discounts applied, floor 2.0.
- privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
- install_url_hijack crx onInstalled opens thebyteseffect.com page — own domain, not 3rd-party; low additional risk.
- uninstall_url_hijack crx setUninstallURL points to thebyteseffect.com/posts/uninstall-url-shortner/ — own domain, not 3rd-party.
- obfuscation_clean crx obfuscation_score=0.0, code_findings_raw empty; no dynamic eval or exfil indicators detected.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- contextMenus low Adds right-click menu; low standalone risk.
- activeTab low Access to current tab only on user interaction; scoped.
- storage low Local data persistence; no cross-origin reach.
- scripting medium Can inject scripts into active tab; limited by activeTab scope.
- https://tinyurl.com/* low Narrow host permission to one URL-shortener service API endpoint.
Pillar Scores
Permissions1.30
Reputation2.00
Network3.50
Webstore1.00
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA
26f9b8eb70fe…
Force block
— not fired
Score recovered
no
Elapsed
25.7s