Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bitcoin Price Ticker

bgddejjmhilkdllbakkgddjodommlimc
Risk Score
2.95
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 6,000
Rating 4.1
Last updated 2026-04-13 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer ivana.frolova1403@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jQuery 3.3.1 bundles 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) — no CSP amplifies XSS risk.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Developer is a free-webmail address (gmail) with no business name — limited accountability.
  • Content script injected into blockchain.com (financial site) — innerHTML sinks in same codebase heighten DOM-XSS impact.
  • No CSP declared (MV3) — innerHTML sinks in jQuery and popup scripts lack mitigating policy.

Evidence

  • gmail_developer_no_name store Developer email ivana.frolova1403@gmail.com; no business name listed — free-webmail identity.
  • generic_privacy_policy store Privacy URL points to myaccount.google.com/privacypolicy — not scoped to this extension; admits data collection + 3rd-party sharing.
  • cve_moderate_jquery crx jquery@3.3.1 carries CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all moderate); fixed in 3.4-3.5.
  • no_csp_dom_sinks crx No content_security_policy + 3 innerHTML sinks across jquery and popup scripts; CVE v2 amplifier applies.
  • content_script_financial_site manifest content_scripts_matches includes https://*.blockchain.com/* — script runs on financial platform pages.
  • verified_and_featured store verified_publisher=true and is_featured_by_google=true — partial trust signal, but publisher is gmail identity.
  • no_bad_hosts_no_affiliates crx threat_intel shows no bad_host_hits, no affiliate_hits, no monetization_hits — clean network signals.
  • recently_updated store Last updated April 2026 (2 months ago) — maintenance risk minimal.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Stores extension state locally; no data exfil risk on its own.
  • background low Keeps alarms/polling alive; standard for a price ticker.
  • alarms low Schedules periodic price fetches; low risk.
  • http://api.coindesk.com/ (host) low Narrow API endpoint for BTC price data; fits stated function.
  • https://api.coindesk.com/ (host) low Narrow API endpoint for BTC price data; fits stated function.
  • https://blockchain.com/* (host) medium Content script injected into blockchain.com — reads page content on financial site.
  • https://*.blockchain.com/* (host) medium Wildcard subdomain content script on financial platform; elevated but scoped.

Pillar Scores

Permissions1.30
Reputation6.50
Network0.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA b1d5eb144239…
Force block — not fired
Score recovered no
Elapsed 30.9s