Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Chrome JavaScript Editor

adfelndhcceedaphfhehpblofeohjmdb
Risk Score
5.37
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 916
Rating
Last updated 2023-02-08 (40 months ago)
Manifest version MV3
CSP present ❌ no
Developer niawkung@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension at all; admits data collection and 3rd-party sharing.
  • Extension has not been updated in 40 months (zombie); abandoned code increases compromise risk.
  • DOM-XSS sink (innerHTML) in editor.js with no CSP, elevating exploitability of any XSS.
  • Developer uses free Gmail address with no business domain or verified-publisher badge.
  • External JS hosts (beautifier.io, codemirror.net, jsdelivr.com) loaded without CSP integrity controls.

Evidence

  • maintenance_stale store Last updated Feb 2023; 40 months since update — zombie tier (+10.0 maintenance).
  • privacy_generic_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
  • no_csp manifest content_security_policy is null; MV3 default is strict but external hosts are referenced without integrity hashes.
  • dom_xss_sink crx editor.js: innerHTML written from variable with no CSP; DOM-XSS risk elevated per FIX B.
  • reputation_gmail_dev store Developer email niawkung@gmail.com; free webmail, no verified publisher, no business domain.
  • external_js_hosts crx 3 external JS hosts: beautifier.io, codemirror.net, www.jsdelivr.com — supply-chain risk without SRI/CSP.
  • featured_by_google store is_featured_by_google=true; partial trust signal, but does not offset staleness or privacy issues.
  • cve_findings crx cve_findings_raw empty; no CVE exposure detected.

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata; moderate risk for a dev tool.
  • contextMenus low Adds right-click menu entries; minimal risk.
  • offscreen low Creates offscreen document; low risk without host permissions.
  • storage low Local key-value storage; no cross-origin exfil vector alone.

Pillar Scores

Permissions1.90
Reputation6.50
Network2.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA 68718e2f555f…
Force block — not fired
Score recovered no
Elapsed 21.6s