Url Shortener
oodfdmglhbbkkcngodjjagblikmoegpa
Risk Score
4.05
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Privacy policy URL fetch failed — privacy posture completely unknown for 300K users.
- jquery@1.9.1 bundled in bootstrap.min.js carries 3 moderate XSS CVEs; no CSP to mitigate.
- No CSP + innerHTML sink in sweetalert2 + vulnerable jQuery = elevated DOM-XSS risk.
- Developer name absent; looks_throwaway flag on t.ly domain reduces accountability.
- Install-URL and uninstall-URL both point to t.ly — install hijack pattern noted.
Evidence
- privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (HTTPError); policy scored +10.0.
- cve_moderate_x3_jquery_1.9.1 crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11023 in jquery@1.9.1 via bootstrap.min.js; fixed_in 3.5.0.
- no_csp_mv3 manifest content_security_policy is null; no CSP mitigations for XSS sinks.
- dom_xss_sink_no_csp crx dom_sink_innerhtml_userctrl in sweetalert2@8.js; csp_present=false triggers +2.0 code quality.
- install_url_hijack crx onInstalled opens https://t.ly/register?ref=extension-install — install URL hijack.
- developer_name_missing_looks_throwaway store developer_name empty; threat_intel.looks_throwaway=true for t.ly domain.
- verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discounts applied to reputation.
- 10_external_js_hosts crx 10 distinct external hosts contacted (api.t.ly, api.rebrandly.com, getbootstrap.com, etc.).
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- activeTab low Access only to current tab on user action; narrow scope for a URL shortener.
- contextMenus low Adds right-click menu items; standard for shortening selected URLs.
- storage low Local settings/preferences storage; limited exfil surface.
Pillar Scores
Permissions1.00
Reputation4.50
Network2.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure3.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA
a4c8c65b6357…
Force block
— not fired
Score recovered
no
Elapsed
27.3s