Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Search It All

ajjjagpncmhojdngglmmpfjiccddcmio
Risk Score
4.48
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 915
Rating 3.9
Last updated 2025-07-28 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer google.chrome@emailcove.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returned HTTP error (fetch_error) — policy unverifiable; scored as missing.
  • Bundled jQuery 1.9.1 has 3 moderate CVEs (XSS); version unfixed well below 3.5.0.
  • developer_name empty and email prefix 'google.chrome' on non-Google domain is mildly deceptive.
  • Extension contacts 6 distinct search engines including ad-supported providers; geo diversity 4 countries.
  • new Function() + innerHTML DOM-sink in bundled jQuery amplify XSS risk from CVEs.

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (HTTPError); scored as no policy → Privacy +10.0.
  • jquery_1_9_1_cve_triple crx 3 moderate CVEs in bundled jquery@1.9.1; all fixed in >=3.4.0. Not in dev/test path.
  • code_function_constructor crx new Function() found in jquery-1.9.1.js; +2.5 code quality.
  • dom_sink_innerhtml crx innerHTML assignment in jquery-1.9.1.js; CSP present but CVEs present → +2.0 code quality.
  • search_engine_count_6 api threat_intel.search_engine_count=6 contacts bing,ddg,google,startpage,yahoo,yandex.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; Reputation discounted.
  • geo_diversity_4_countries api JS hosts span CA/HK/SG/US (count=4); category not VPN/Adblock → Network +1.5.
  • developer_name_missing store developer_name is empty string; email prefix mimics Google brand on emailcove.com.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • activeTab low Access only to currently active tab on user gesture; narrow scope.
  • storage low Local data persistence; no exfil risk on its own.
  • tabs medium Can read URLs and titles of open tabs; moderate privacy surface.
  • declarativeContent low Used to show/hide page action based on URL; read-only rule matching.
  • contextMenus low Adds right-click menu entries; low standalone risk.

Pillar Scores

Permissions1.30
Reputation3.50
Network2.50
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality4.50
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA def202d92fa3…
Force block — not fired
Score recovered no
Elapsed 29.7s