Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dark Night Mode

bhbekkddpbpbibiknkcjamlkhoghieie
Risk Score
4.43
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Accessibility
Installs 60,000
Rating 4.2
Last updated 2025-01-15 (17 months ago)
Manifest version MV3
CSP present ❌ no
Developer DarkNightMode@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • jQuery 2.2.2 bundles 4 moderate XSS CVEs; fixed version is 3.5.0 — not updated after 17 months.
  • No developer name provided; gmail.com dev email reduces accountability.
  • <all_urls> host_permissions with content scripts on every visited page broadens attack surface.
  • Extension stale at 17 months with unpatched vulnerable library in an extension touching all sites.

Evidence

  • generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → privacy pillar 10.0.
  • vulnerable_jquery crx jquery@2.2.2 bundled with 4 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); fixed in 3.5.0.
  • cve_amplifier_applied crx No CSP + moderate CVEs in DOM-manipulation lib (jquery) → CVE pillar ×1.5 amplifier applied.
  • no_developer_name store developer_name is empty; only gmail.com contact available, reducing accountability.
  • content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] with host_permissions=<all_urls>; JS injected into every visited page.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partial reputation discount applied (capped at -1.0 due to months_since_update=17>18 threshold near).
  • maintenance_stale store Last updated January 2025; 17 months since update → maintenance score 6.0 (6-12 month band).
  • no_csp manifest content_security_policy=null on MV3 extension; amplifies CVE risk for bundled jQuery.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.2.2 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.2.2 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.2.2 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.2.2 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • tabs medium Can read tab URLs; moderate risk for a theming extension.
  • storage low Persists user settings locally; standard for theming tools.
  • <all_urls> (host_permissions) high Content scripts injected on every site; necessary for dark-mode but broad surface.

Pillar Scores

Permissions4.00
Reputation5.50
Network0.00
Webstore1.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA 9fd3953335e0…
Force block — not fired
Score recovered no
Elapsed 26.1s