Tabs Manager
okeooekaaniggaignhhfeddohlcjadkd
Risk Score
4.97
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- scripting + <all_urls> host permission allows JS injection into every page visited; broad capability for small utility.
- Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
- Developer uses free Gmail address with no verified business identity; no domain age data available.
- last_updated missing — maintenance posture unknown; cannot assess staleness or abandonment risk.
- Featured badge provides some trust signal, but free-webmail developer with generic privacy policy offsets it.
Evidence
- broad_host_permissions manifest host_permissions=["<all_urls>"] + scripting permission enables script injection on all sites.
- generic_privacy_policy store Policy URL is myaccount.google.com/privacypolicy — Google account policy, scope_extension=false, admits data_collection+third_party_sharing.
- free_webmail_developer store Developer email islam.s.elbanna@gmail.com; domain_age_ct not queried (free webmail); no verified business.
- featured_by_google store is_featured_by_google=true; provides partial reputation discount.
- no_csp manifest content_security_policy=null on MV3; MV3 default CSP applies so no MV2 penalty, but no explicit hardening.
- no_code_findings crx code_findings_raw=[], obfuscation_score=0.0; no malicious code patterns detected in 9 JS files.
- maintenance_unknown store last_updated empty and months_since_update=null; cannot confirm active maintenance.
- jquery_3_7_1_no_cves crx jquery@3.7.1 detected; cve_findings_raw empty — no known vulnerabilities at this version.
Permissions Breakdown
- tabs medium Access to tab URLs, titles, and metadata across all windows.
- activeTab low Temporary access to the currently active tab on user action.
- storage low Local extension storage; low direct risk.
- scripting high Can inject scripts into pages; combined with <all_urls> host permission this is broad capability.
- <all_urls> (host_permissions) high Grants access to all sites; paired with scripting enables arbitrary JS injection on every page.
- <all_urls> (content_scripts) high Content scripts run on every URL the user visits, expanding data-access surface.
Pillar Scores
Permissions5.50
Reputation6.50
Network2.00
Webstore1.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:01
Listing SHA
e2162749847c…
Force block
— not fired
Score recovered
no
Elapsed
22.2s