Skip Ads - Adblocker for YouTube
lkahpjghmdhpiojknppmlenngmpkkfma
Risk Score
5.64
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy is Google's generic account policy — not scoped to this extension; collects+shares data per classification.
- YouTube brand impersonation by unverified free-webmail developer (adskiper@outlook.com).
- jQuery 2.2.4 bundled with 4 medium CVEs (XSS); no CSP present amplifies DOM-sink risk.
- Description promises ad-blocking but lacks declarativeNetRequest/webRequest — functional mismatch signal.
- Content scripts on <all_urls> give broad read/write capability across all sites visited.
Evidence
- brand_impersonation store brand_mention.is_impersonation=true; 'youtube' referenced, developer not confirmed owner; free-webmail address.
- generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
- cve_jquery_2.2.4 crx 4 medium-severity CVEs in bundled jquery@2.2.4 (CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023).
- no_csp manifest content_security_policy is null; CVE amplifier applies for jquery XSS risk.
- description_mismatch store Promises ad-blocking but neither declarativeNetRequest nor webRequest declared.
- host_permission_all_urls manifest host_permissions=[<all_urls>] + content_scripts on <all_urls>; broad site access.
- free_webmail_dev store developer_email=adskiper@outlook.com; no verified business domain.
- is_featured_by_google store is_featured_by_google=true; partially mitigates reputation but does not resolve policy/CVE concerns.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@2.2.4 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@2.2.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@2.2.4 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@2.2.4 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- storage low Stores extension settings locally; low standalone risk.
- <all_urls> (host_permissions) high Content scripts injected on every site; broad read/modify capability.
Pillar Scores
Permissions5.50
Reputation7.50
Network2.00
Webstore6.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA
b1c200160c9d…
Force block
— not fired
Score recovered
no
Elapsed
40.3s