Redux DevTools
lmhkpmbekcpmknklioeibfkpmmfibljd
Risk Score
5.18
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE in bundled underscore@1.8.3 (ACE) + high-severity CVE — both unfixed, running on 1M installs.
- new Function() constructor in page.bundle.js enables arbitrary code execution from inspected app state.
- 3x innerHTML DOM-XSS sinks across devpanel, options, remote bundles compound CVE exposure.
- Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing.
- 15-month stale update with critical CVEs and broad <all_urls> content script access raises supply-chain risk.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed_in 1.12.1 — current version unfixed.
- high_cve_bundled_lib crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed_in 1.13.8 — unfixed.
- function_constructor crx new Function('return '+e)() in page.bundle.js — arbitrary code path from inspected app data.
- dom_xss_sinks crx innerHTML user-controlled sinks in devpanel, options, remote bundles — 3 distinct files.
- broad_host_access manifest content_scripts on <all_urls> + host_permissions http://*/* https://*/* file:///*
- generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
- stale_update store Last updated April 2025 — 15 months since update; critical CVEs unpatched in that window.
- no_verified_publisher store Not verified publisher, not featured; developer email on personal domain timdorr.com (resolves).
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- notifications medium Can surface alerts to user; medium risk without broad host pairing.
- contextMenus low Adds right-click menu items; low standalone risk.
- storage low Local state persistence; low risk.
- file:///* medium Content script access to local files; moderate sensitivity.
- http://*/* high Broad HTTP host access — content scripts on all HTTP sites.
- https://*/* high Broad HTTPS host access — content scripts on all HTTPS sites.
- content_scripts:<all_urls> high Injects JS into every page; primary attack surface if compromised.
Pillar Scores
Permissions5.50
Reputation5.00
Network0.00
Webstore1.50
Maintenance6.00
Privacy10.00
Code Quality7.50
CVE Exposure7.00
Scoring History
| <fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx | 5.84 | Medium | review | 2026-08-13 |
| <fsssiedx{'sssiedx | 5.40 | Medium | block | 2026-08-13 |
| <fsssiedx{$'sssiedx | 6.08 | High | review | 2026-08-13 |
| fsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx | 5.04 | Medium | review | 2026-08-13 |
| fsssiedxd'sssiedx | 6.36 | High | review | 2026-08-13 |
| sssieddrubricxsx | 6.37 | High | review | 2026-08-13 |
| "dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") | 6.24 | High | block | 2026-08-05 |
| <th:t="${dfb}#foreach | 6.14 | High | block | 2026-08-05 |
| v3.6&n951831=v988453 | 5.57 | Medium | review | 2026-08-05 |
| v3.6'"()&%<zzz><ScRiPt >ObOc(9154)</ScRiPt> | 6.02 | High | block | 2026-07-29 |
| v3.6 | 5.18 | Medium | block | 2026-07-08 |
Bookkeeping
Rubric v3.6
Scored at 2026-07-08 13:00
Listing SHA
e11cff822daa…
Force block
— not fired
Score recovered
no
Elapsed
—