Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Color Picker by AdCreative.ai

bijgpkifioecdiebmfdlecnbgiommlmf
Risk Score
5.75
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 10,000
Rating 4.9
Last updated 2024-04-17 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer tufan@adcreative.ai
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@1.11.1 bundles 3 medium CVEs (XSS); no CSP amplifies exploitability on <all_urls> content script.
  • Privacy policy does not scope to this extension and admits data collection + third-party sharing (score 10.0).
  • Extension stale 26 months with vulnerable jquery; no update despite public CVE disclosures.
  • Content script runs on <all_urls> with no CSP, expanding attack surface for bundled XSS vulnerabilities.
  • Dynamic <script> injection in jquery.js combined with absent CSP enables potential remote code loading paths.

Evidence

  • vulnerable_jquery crx jquery@1.11.1 bundled; 3 medium CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in 3.5.0.
  • no_csp crx content_security_policy is null; MV3 default applies but no explicit restriction on script sources.
  • content_script_all_urls manifest content_scripts_matches: [<all_urls>] — DOM access on every site visited.
  • privacy_policy_not_scoped store Policy fetched but scope_extension==false; admits data_collection and third_party_sharing without extension scope.
  • stale_extension store Last updated April 2024; 26 months since update with known CVEs unfixed.
  • dynamic_script_creation crx script_src_dynamic signal in js/jquery.js; JSONP transport creates dynamic script elements.
  • no_developer_name store developer_name is empty string; identity relies solely on email tufan@adcreative.ai.
  • featured_by_google store is_featured_by_google==true; partial trust signal, but does not offset CVE/privacy gaps.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.11.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.11.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.11.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Used to persist color picker settings/history locally.
  • content_scripts:<all_urls> high Content script injected on all URLs enables DOM access across every site the user visits.

Pillar Scores

Permissions3.30
Reputation5.00
Network3.00
Webstore3.00
Maintenance8.50
Privacy10.00
Code Quality5.50
CVE Exposure5.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA 2fdc5acc730e…
Force block — not fired
Score recovered no
Elapsed 25.7s