Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WOT: Website Security & Safety Checker

bhmmomiinigofkjcapegjjndpbikblnp
Risk Score
4.02
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 700,000
Rating 4.5
Last updated 2026-03-13 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@mywot.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • underscore@1.8.3 bundles critical CVE-2021-23358 (arbitrary code execution) and high CVE-2026-27601 (DoS); not patched.
  • broad host access (http://*/* + https://*/*) combined with scripting and webRequest enables full page read/modify on every site.
  • new Function() constructor in background.js and innerHTML sinks in growthbook.js/react-dom create code-execution surface.
  • Privacy policy discloses third-party data sharing; scoped but extension collects browsing data on all visited URLs.
  • bit.ly affiliate/cloaking redirector present in js_external_hosts — obfuscates final redirect destination.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (ACE, critical); fixed in 1.12.1 — still at 1.8.3.
  • high_cve_bundled_lib crx underscore@1.8.3 has CVE-2026-27601 (DoS, high); fixed in 1.13.8.
  • broad_host_permissions manifest host_permissions include http://*/* and https://*/* plus content_scripts on *://*/*. Full site access.
  • function_constructor crx new Function('return this') in background.js — dynamic code construction path.
  • dom_xss_sink crx innerHTML assignment in growthbook.js and react-dom.min.js; csp_present but unsafe-inline on style-src only.
  • affiliate_hit crx bit.ly in js_external_hosts — generic short-link/affiliate cloaking redirector.
  • verified_publisher_featured store Extension is verified publisher AND featured by Google; domain mywot.com resolves; email on same domain.
  • third_party_sharing_disclosed api Privacy policy fetched; scope_extension=true, retention=true, third_party_sharing=true — disclosed but present.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata; needed for site-rating overlays.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • webNavigation medium Tracks navigation events across all sites; broad reach.
  • webRequest high Observe all HTTP requests across http://*/* and https://*/*.
  • declarativeNetRequest medium Rule-based request blocking; expected for security tool.
  • declarativeNetRequestFeedback medium Read matched blocking rules; low additional risk.
  • storage low Local extension data storage; standard.
  • scripting high Programmatic script injection into pages; paired with broad host permissions.
  • alarms low Scheduled background tasks; low risk.
  • http://www.mywot.com/* low Dev-owned domain; scoped host access.
  • http://api.mywot.com/* low Dev-owned API domain; scoped.
  • https://api.mywot.com/* low Dev-owned API domain; scoped.
  • http://*/* high Full HTTP host access — all sites.
  • https://*/* high Full HTTPS host access — all sites.

Pillar Scores

Permissions6.10
Reputation2.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy1.00
Code Quality5.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA 377f76e7f987…
Force block — not fired
Score recovered no
Elapsed 32.5s