Unpaywall
iplffkdpngmdjhlpjmppncnlhomiipha
Risk Score
3.29
Risk Level:
Low
Recommendation:
🟢 LOW RISK — review
Top Risks
- jquery@3.1.1 bundles 3 moderate CVEs (XSS); unfixed since 2020, fixed_in 3.5.0
- Privacy policy fetched but scope_extension=false and length=120; too generic to be adequate
- 17 months since last update; stale for a 900K-install extension with known CVEs
- Content scripts run on <all_urls> giving broad page-read reach across all sites
- 5-country JS host diversity (CA/FR/GB/IN/US) slightly elevates network surface
Evidence
- verified_publisher + featured store Verified publisher badge and Google Featured badge; reputation floor 2.0 applied.
- jquery@3.1.1 CVEs crx 3 moderate-severity jQuery XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
- privacy_policy_too_short api Policy length=120 chars, scope_extension=false, data_collection=false; v3 FIX A => +9.0.
- content_scripts <all_urls> manifest Runs on all pages; function is scholarly article lookup so justified-broad applies partially.
- stale_update store 17 months since update; maintenance score +6.0 (12-24mo band).
- no_bad_hosts_no_monetization api threat_intel: bad_host_hits=[], monetization_hits=[], affiliate_hits=[]; clean.
- obfuscation_score=0_code_findings_empty crx No obfuscation, no suspicious code findings; clean JS scan.
- host_geo_diversity crx JS hosts span 5 countries (CA,FR,GB,IN,US); academic publishers, not ad-tech.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@3.1.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.1.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- storage low Local state only; no cross-origin data access.
- host_permissions: *://*.oadoi.org/* low Scoped to developer's own API domain; narrow.
- content_scripts: <all_urls> medium Runs JS on all pages; needed to detect DOIs but broad reach.
Pillar Scores
Permissions1.80
Reputation2.00
Network1.50
Webstore2.00
Maintenance6.00
Privacy9.00
Code Quality1.50
CVE Exposure3.00
Scoring History
| sssiedn6f05e74bdp727562726963xsx | 3.52 | Low | review | 2026-09-09 |
| sssiedndfdf31abdp727562726963xsx | 3.33 | Low | review | 2026-09-07 |
| v3.6 | 3.29 | Low | review | 2026-06-17 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-17 08:18
Listing SHA
3b1f74e9429c…
Force block
— not fired
Score recovered
no
Elapsed
—