Tab Suspender
laameccjpleogmfhilmffpdbiibgbekf
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- new Function() constructor present in all 6 JS files — dynamic code execution risk with broad host access.
- Privacy policy is only 16 chars, not scoped to this extension, and data_collection=false with no retention info — effectively inadequate.
- Free-webmail developer (gmail) with no developer name; verified/featured discounts partially offset but not eliminated.
- Broad host permissions (http://*/*, https://*/*) + scripting allow arbitrary content injection on every site.
- 19 months since last update; v3.5 invariant 0c caps verified-publisher discount due to stale update.
Evidence
- free_webmail_developer store Developer email tayloreolivian4@gmail.com is free webmail; no developer name provided.
- verified_publisher_featured store Extension has verified_publisher=true and is_featured_by_google=true; discount capped at -1.0 due to stale 19mo.
- broad_host_permissions manifest host_permissions include http://*/* and https://*/* combined with scripting permission.
- function_constructor_all_files crx new Function() constructor found in all 6 scanned JS files; potential dynamic code execution surface.
- privacy_policy_inadequate api Policy fetched but only 16 chars, scope_extension=false, data_collection=false, third_party_silence=true.
- stale_update store Last updated January 22, 2025; 19 months since update triggers maintenance risk.
- no_csp manifest content_security_policy is null; no CSP declared on MV3 extension.
- cve_clean crx cve_findings_raw is empty; no known CVEs in bundled libraries.
Permissions Breakdown
- storage low Standard local state persistence; low risk.
- unlimitedStorage low Allows larger local storage quota; minimal risk.
- tabs medium Can read tab URLs/titles across all open tabs.
- favicon low Read-only favicon access; low risk.
- scripting high Combined with <all_urls> host perms, can inject JS into any page.
- contextMenus low UI surface addition only; low risk.
- system.memory low Read-only system memory info; low risk.
- http://*/* high Broad host access to all HTTP sites; enables content injection.
- https://*/* high Broad host access to all HTTPS sites; enables content injection.
Pillar Scores
Permissions6.00
Reputation6.50
Network2.00
Webstore1.00
Maintenance6.00
Privacy9.00
Code Quality5.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 07:55
Listing SHA
9207fee5ba1e…
Force block
— not fired
Score recovered
no
Elapsed
—