Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Easy Color Picker

bgahcehknhgmjoggmkibghafppcfoaci
Risk Score
5.32
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 8,000
Rating 4.5
Last updated 2025-08-31 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer webtools.any@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but does not scope to this extension and admits third-party sharing — scores maximum privacy risk.
  • Bundled jquery@1.12.4 has 4 medium-severity XSS CVEs; no CSP present amplifies exploitability.
  • Broad host permissions (https://*/*, http://*/*) paired with scripting allow JS injection on every site visited.
  • Developer is free-webmail Gmail account with no business name, reducing accountability.
  • No CSP with vulnerable DOM-manipulation library (jQuery) increases XSS attack surface on injected content.

Evidence

  • broad_host_permissions manifest https://*/* and http://*/* grant script injection access to all websites via scripting permission.
  • jquery_cve_cluster crx jquery@1.12.4 bundles 4 medium-severity XSS CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023).
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit CSP hardens against CVE-affected jQuery.
  • privacy_policy_inadequate api Policy fetched (101964 chars) but scope_extension=false, data_collection=false, third_party_sharing=true — generic, not scoped.
  • free_webmail_dev_no_name store developer_email=webtools.any@gmail.com; developer_name empty; no verified business identity.
  • install_url_hijack crx install_url_hijack=true, target=/debug-tab.html — opens internal debug page on install.
  • google_analytics_hit crx monetization_hits includes www.google-analytics.com; telemetry present.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true provide some trust offset, but do not override privacy/CVE risks.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.12.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.12.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • activeTab medium Access to current tab content on user action; low standalone risk but combined with scripting increases surface.
  • storage low Local data persistence only; no cross-origin risk.
  • scripting high Allows dynamic JS injection into pages; paired with broad host permissions is a high-impact capability.
  • https://*/* high Broad host access across all HTTPS sites enables scripting injection everywhere.
  • http://*/* high Broad host access across all HTTP sites, extends injection surface to insecure pages.

Pillar Scores

Permissions5.50
Reputation6.00
Network3.50
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality3.50
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA 1aae6a4afd7e…
Force block — not fired
Score recovered no
Elapsed 28.2s