Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Url Shortener for Google Chrome™

aacgdipdhmilcpcpbdcloifondogabco
Risk Score
6.24
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 200,000
Rating 4.3
Last updated 2023-10-18 (35 months ago)
Manifest version MV3
CSP present ❌ no
Developer mica.muller2024@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Google brand impersonation: title claims '™' affiliation but developer is unverified gmail user with no dev name.
  • Privacy policy fetch failed (ConnectionError) and URL domain is unrelated Facebook tool — treated as no valid policy.
  • Install/uninstall URL hijack flags set; both targets unresolvable but pattern is consistent with monetization shell.
  • jquery@2.2.4 bundles 4 moderate CVEs (XSS); no CSP present — v2 ×1.5 CVE amplifier applies.
  • 32 months since last update with 200k installs — abandoned high-reach extension with known-vulnerable library.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands=['google']; developer_email=gmail.com; confirmed_owner=false.
  • privacy_policy_unreachable api Privacy policy fetch_error:ConnectionError; URL domain is unrelated Facebook tool. Scored as fetched=false → +10.0.
  • install_uninstall_hijack crx install_url_hijack=true AND uninstall_url_hijack=true; targets null but flags present per manifest scan.
  • cve_vulnerable_jquery crx jquery@2.2.4: CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251 — all moderate XSS; fixed_in 3.5.0.
  • no_csp_with_cves crx csp_present=false + 4 moderate CVEs in jquery (DOM-manipulation lib) → CVE pillar ×1.5 amplifier applied.
  • stale_abandoned store 32 months since update; 200k installs; MV3 but jquery not updated. +8.5 maintenance + zombie booster +1.0 capped at 10.
  • free_webmail_no_devname store developer_email=gmail.com; developer_name empty; no business website → reputation floor ≥7.5 triggered.
  • dom_sink_innerhtml crx code_findings_raw: dom_sink_innerhtml_userctrl in data/libs/Localize.js; no CSP present → +2.0 (FIX B).

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.2.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.2.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • activeTab low Scoped to user-initiated action on current tab only.
  • storage low Local storage for settings; no cross-site capability.
  • host:https://chart.googleapis.com/* low Narrow Google API host for URL shortening/QR generation.
  • host:https://tinyurl.com/* low Narrow TinyURL host for URL shortening service.

Pillar Scores

Permissions0.60
Reputation8.00
Network2.00
Webstore7.00
Maintenance8.50
Privacy10.00
Code Quality2.50
CVE Exposure4.50

Scoring History

sssiedn3f612372dp727562726963xsx 6.39 High block 2026-09-08
fsssiedxn14d9af02za'n14d9af02zsssiedx 6.52 High block 2026-09-06
sssiedn95da1c86dp727562726963xsx 6.38 High block 2026-09-06
v3.6 6.24 High block 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:14
Listing SHA afd000eac20b…
Force block — not fired
Score recovered no
Elapsed 34.6s