Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Scrubber for Instagram

apondjajmejlodhkaenofcicoiiekghf
Risk Score
6.19
Risk Level: High
Recommendation: 🚫 BLOCK
Category Entertainment
Installs 9,000
Rating 3.9
Last updated
Manifest version MV3
CSP present ❌ no
Developer support@georgemike.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • No update date available — extension may be abandoned; maintenance pillar at maximum.
  • jquery@1.12.4 bundles 4 medium XSS CVEs; no CSP amplifies DOM-XSS risk on Instagram pages.
  • Privacy policy fetched but does not scope to this extension; admits third-party sharing without disclosure.
  • Brand impersonation: 'Instagram' in name, developer not a confirmed owner; verified+featured does not clear this.
  • install_url_hijack and uninstall_url_hijack both flagged; onInstalled/onUninstalled open 3rd-party URLs.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'instagram'; developer not confirmed owner.
  • cve_jquery_medium_x4 crx jquery@1.12.4 carries CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251 (all medium).
  • no_csp_plus_cve_dom_sink crx csp_present=false; dom_sink_innerhtml_userctrl in InstaUtils.js with CVE-laden jQuery = elevated XSS risk.
  • install_uninstall_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets not disclosed.
  • privacy_policy_inadequate store Policy fetched; scope_extension=false, data_collection=false, third_party_sharing=true → +9.0 privacy.
  • no_last_updated store months_since_update=null; last_updated empty; maintenance scored at maximum (10.0).
  • external_js_hosts crx js_external_hosts: chrome.google.com, docs.google.com, getbootstrap.com, www.georgemike.com (4 domains).
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; caps applied but impersonation+CVEs limit discount.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.12.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.12.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Stores local extension state; no cross-site data risk.
  • host:https://instagram.com/* medium Content script runs on Instagram pages; scoped to single domain.
  • host:https://*.instagram.com/* medium Covers all Instagram subdomains; required for stated function.

Pillar Scores

Permissions2.30
Reputation5.50
Network3.50
Webstore4.50
Maintenance10.00
Privacy9.00
Code Quality6.50
CVE Exposure6.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA 006ec76a3532…
Force block — not fired
Score recovered no
Elapsed 29.6s