Search All
kpdkbemdpepjjppbfgeapjienologapa
Risk Score
6.14
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- jquery@1.7.1 bundles 5 moderate CVEs (XSS); version far behind fixed releases up to 3.5.0.
- Content scripts on <all_urls> with DOM innerHTML sink in process.js creates XSS attack surface on every page.
- Privacy policy fetched but scope_extension=false AND admits data_collection+third_party_sharing — scores 10.0 (v3.5 rule D).
- code_quality 7.5 (function_constructor + script_src_dynamic + innerHTML sink + CVE combo) triggers block threshold.
- History + tabs + bookmarks + <all_urls> gives broad browsing profile capture capability; maintenance date unknown.
Evidence
- cve_jquery_1.7.1 crx 5 moderate CVEs in bundled jquery@1.7.1; fixed_in ranges 1.9.0–3.5.0; library not updated.
- code_function_constructor crx new Function() constructor in js/jquery.js — dynamic code execution path.
- code_script_src_dynamic crx Dynamic <script> element creation in js/jquery.js — remote script loading risk.
- code_innerhtml_sink crx innerHTML assigned from variable in js/process.js; combined with CVEs raises XSS risk.
- privacy_policy_scope_mismatch api Policy admits data_collection+third_party_sharing but scope_extension=false — generic policy, triggers +10.0.
- host_permissions_all_urls manifest <all_urls> content scripts on every page combined with history/tabs/bookmarks access.
- js_external_hosts_12 crx 12 external JS hosts including go.redirectingat.com and www.searcho.com — potential affiliate/redirect surface.
- featured_by_google store is_featured_by_google=true; reduces reputation risk but does not override code/privacy findings.
CVE Exposures (5)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2012-6708 | jquery@1.7.1 | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2019-11358 | jquery@1.7.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.7.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-7656 | jquery@1.7.1 | moderate | 1.9.0 | Cross-Site Scripting in jquery |
| CVE-2015-9251 | jquery@1.7.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- contextMenus low Adds right-click menu items; low standalone risk.
- unlimitedStorage low Allows extended local storage; no data exfil by itself.
- storage low Standard local data persistence.
- tabs medium Can read tab URLs/titles across all open tabs.
- bookmarks medium Full read/write access to user bookmarks.
- history medium Full browsing history access — sensitive PII surface.
- offscreen low Off-screen document rendering; low direct risk.
- activeTab low Scoped to current tab on user action.
- favicon low Read favicon URLs; minimal risk.
- <all_urls> (host_permissions) high Content scripts run on every page; broad DOM/data access across all sites.
- *://*.images.google.com/ (host_permissions) low Specific subdomain; narrower than <all_urls> but overlaps with it.
Pillar Scores
Permissions7.50
Reputation3.50
Network3.50
Webstore4.50
Maintenance5.00
Privacy10.00
Code Quality7.50
CVE Exposure5.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA
6f8ac3d31445…
Force block
— not fired
Score recovered
no
Elapsed
35.1s