Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Language Learning with Netflix & YouTube-AFL

bekopgepchoeepdmokgkpkfhegkeohbl
Risk Score
3.00
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 100,000
Rating 3.9
Last updated 2026-07-29 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer welcome@appforlanguage.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); not patched.
  • Privacy policy points to Google's own policy (myaccount.google.com) — not scoped to this extension at all.
  • Brand impersonation: extension name uses 'Netflix' and 'YouTube' but developer is not a confirmed owner.
  • 12 distinct external JS hosts including funfluen.com subdomains; broad network surface for language app.
  • No developer name listed in store; increases accountability gap despite verified publisher badge.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE) and CVE-2026-27601 (high, DoS); fixed_in 1.12.1/1.13.8.
  • privacy_policy_not_scoped store Privacy policy URL is Google's generic account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • brand_impersonation store brands_mentioned=[youtube,netflix], confirmed_owner=false, is_impersonation=true per brand_mention.
  • broad_external_hosts crx 12 external JS hosts: appforlanguage.com subdomains + funfluen.com subdomains + fb.me + github.com.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partially mitigates reputation concerns.
  • no_developer_name store developer_name is empty string; reduces accountability despite having developer email.
  • react_16_13_1_bundled crx react@16.13.1 bundled; below 18.x but no CVE flagged; CSP present (self-only) mitigates XSS risk.
  • content_scripts_payment_gateway crx Content scripts run on appforlanguage.com payment-gateway paths; could access payment page DOM.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Stores user preferences/state locally; minimal risk.
  • tts low Text-to-speech for language learning; fits stated function.
  • https://appforlanguage.com/* low Developer's own domain; payment gateway content scripts.
  • https://clients5.google.com/* low Google API endpoint; narrow scope.
  • *://youtube.com/* medium Broad access to YouTube; justified by stated language-learning function.
  • *://netflix.com/* medium Broad access to Netflix; justified by stated language-learning function.

Pillar Scores

Permissions2.00
Reputation5.00
Network1.50
Webstore4.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure7.00

Scoring History

sssiednbd495533dp727562726963xsx 4.52 Medium review 2026-08-28
<fsssiedxi&#x27;sssiedx 4.09 Medium review 2026-08-18
<fsssiedxa xx psssiedx 2.79 Low review 2026-08-18
fsssiedx<sssiedx 4.42 Medium review 2026-08-18
%22fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.01 Medium review 2026-08-17
&#x27;fsssiedxa$"sssiedx 4.03 Medium review 2026-08-17
fsssiedxa$'sssiedx 4.36 Medium review 2026-08-17
<fsssiedxa'sssiedx 4.08 Medium review 2026-08-17
v3.6"><script>R1yf(9449)</script> 2.75 Low review 2026-08-05
dfb__${98991*97996}__::.x 4.03 Medium review 2026-08-05
dfb[[${98991*97996}]]xca 2.75 Low review 2026-08-05
v3.6&n930475=v985507 4.08 Medium review 2026-08-05
%F6"onmouseover=RTSa(94535)// 5.05 Medium review 2026-08-04
v3.6&n992863=v915276 2.88 Low review 2026-08-04
<fsssiedxa&#x27;sssiedx 4.28 Medium review 2026-07-29
<fsssiedxa&#x22;sssiedx 4.08 Medium review 2026-07-29
<fsssiedxa"sssiedx 4.36 Medium review 2026-07-29
<fsssiedxa$'sssiedx 4.33 Medium review 2026-07-29
fsssiedxa<sssiedx 4.08 Medium review 2026-07-29
<fsssiedxa$"sssiedx 4.58 Medium block 2026-07-29
%22fsssiedxa sssiedx 2.59 Low review 2026-07-29
%27fsssiedxa$"sssiedx 4.22 Medium review 2026-07-29
&#x22;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.52 Medium review 2026-07-29
fsssiedxa$"sssiedx 4.05 Medium review 2026-07-29
v3.69772/"();}]9996 4.03 Medium review 2026-07-29
v3.6" 9Sio=EqKI([!+!]) BQQ=" 4.26 Medium review 2026-07-29
dfb{{98991*97996}}xca 4.30 Medium review 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 4.28 Medium review 2026-07-29
<th:t="${dfb}#foreach 4.07 Medium review 2026-07-29
'"()&%<zzz><ScRiPt >EqKI(9753)</ScRiPt> 4.10 Medium review 2026-07-29
v3.6&n971466=v938500 4.10 Medium review 2026-07-29
sssieddrubricxsx 2.43 Low review 2026-07-28
v3.6 3.00 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA ff9efacaae6d…
Force block — not fired
Score recovered no
Elapsed 26.3s