Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Twitter Demetricator

abcocamcgfjfdcpfopgpadihhbjbdcem
Risk Score
5.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 3,000
Rating 4.5
Last updated 2023-01-17 (41 months ago)
Manifest version MV3
CSP present ❌ no
Developer bgrosser@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned: 41 months since last update with known unfixed jQuery CVEs (3x medium XSS).
  • Privacy policy is Google's generic policy — does not scope data collection to this extension at all.
  • jQuery 3.3.1 bundled without CSP; CVE amplifier applies (jQuery DOM-manipulation lib, no CSP, medium CVEs).
  • Developer uses free webmail (gmail) with no dev name listed; brand_mention flags Twitter impersonation.
  • dom_sink_innerhtml_userctrl finding in td.user.js combined with no CSP increases XSS exploitability.

Evidence

  • stale_extension store Last updated January 2023; 41 months since update. Triple-stale: >24mo + CVEs + MV3 (MV2 bonus N/A but staleness is critical).
  • cve_jquery_medium_x3 crx jquery@3.3.1 carries CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all medium); fixed_in 3.5.0 not applied.
  • no_csp manifest content_security_policy is null; CVE amplifier ×1.5 applies to CVE pillar (jQuery DOM-manip lib + no CSP).
  • generic_privacy_policy store Privacy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
  • brand_impersonation store brand_mention.is_impersonation=true for 'twitter'; developer is free webmail with no dev name; featured badge present.
  • dom_xss_sink crx dom_sink_innerhtml_userctrl in td.user.js; no CSP and CVEs present → elevated +2.0 code quality penalty.
  • free_webmail_no_devname store developer_email=bgrosser@gmail.com, developer_name empty; verified_publisher=true and featured partially offset.
  • js_external_hosts crx Extension references bengrosser.com and minus.social; both appear dev-controlled; no bad_host_hits.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Can read tab URLs/titles; moderate privacy exposure.
  • storage low Persists local settings; no cross-site exposure.
  • content_scripts *://*.twitter.com/* medium Injects JS/CSS into Twitter pages; scoped to single domain.

Pillar Scores

Permissions1.30
Reputation5.50
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA 818b1942fc42…
Force block — not fired
Score recovered no
Elapsed 29.0s