Bookmark Manager
idakfiahffeejfhghndaboolmmhbnepn
Risk Score
4.44
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy admits data collection and third-party sharing without extension-specific scope — worst-case privacy posture.
- 7 unpatched medium-severity CVEs in bundled jquery@3.3.1 and jquery-ui@1.12.1; DOM-XSS sink in sessions.js amplifies risk.
- DOM-XSS sink (innerHTML from variable) combined with no CSP and vulnerable jQuery raises exploitability.
- <all_urls> host access combined with history and tabs grants broad surveillance capability.
- Developer is free-webmail gmail address with no developer name disclosed, reducing accountability.
Evidence
- privacy_policy_admits_collection_and_sharing_no_scope api Policy fetched: scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D → +10.0 privacy.
- 7_medium_cves_in_jquery_jquery-ui crx jquery@3.3.1 (3 CVEs) and jquery-ui@1.12.1 (4 CVEs), all moderate, all below fixed_in versions.
- dom_xss_sink_no_csp crx innerHTML from user-controlled var in sessions.js; csp_present=false triggers +2.0 code quality penalty (FIX B).
- broad_host_access_with_history manifest <all_urls> + history + tabs; no justified-broad discount (not an adblock/VPN/privacy category).
- free_webmail_dev_no_name store developer_email=aureollabs@gmail.com, developer_name empty; gmail dev with no business website.
- verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; discounts applied but capped where applicable.
- cve_amplifier_no_csp_jquery crx No CSP + medium CVEs in jQuery (DOM-manipulation lib): ×1.5 CVE amplifier applied → cve_pillar=5.0.
- rating_below_3_5 store Rating 3.4; count unknown. Below 4.5 threshold so no positive adjustment; insufficient data for negative trigger.
CVE Exposures (7)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-41182 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `altField` option of the Datepicker widget in jquery-ui |
| CVE-2021-41184 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in the `of` option of the `.position()` util in jquery-ui |
| CVE-2022-31160 | jquery-ui@1.12.1 | moderate | 1.13.2 | jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in |
| CVE-2021-41183 | jquery-ui@1.12.1 | moderate | 1.13.0 | XSS in `*Text` options of the Datepicker widget in jquery-ui |
| CVE-2019-11358 | jquery@3.3.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.3.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- tabs medium Allows reading tab URLs/titles; reasonable for bookmark manager.
- history medium Full browsing history access; broad capability for a bookmark tool.
- bookmarks medium Core stated function; read/write all bookmarks.
- <all_urls> high Host access to all URLs; broad capability paired with history/tabs.
- storage low Local extension data storage; low risk.
- favicon low Read favicon URLs; minimal risk.
- sidePanel low UI surface only; low risk.
Pillar Scores
Permissions6.00
Reputation5.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure5.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA
77dd4c13fdca…
Force block
— not fired
Score recovered
no
Elapsed
53.4s