Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WebWise Search

caapepgfdmamgkidjnhijgbiefidebdb
Risk Score
6.53
Risk Level: High
Recommendation: 🚫 BLOCK
Category Other
Installs
Rating
Last updated 2024-05-07 (28 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@web-wise-search.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override silently redirects all queries to dev-controlled endpoint with no verified identity.
  • Developer domain does not resolve and privacy policy URL is unreachable — effective no-policy state.
  • Three bundled jQuery versions (1.9.1, 1.12.4, 3.3.1) carry 4 distinct medium CVEs; no CSP amplifies XSS risk.
  • Extension last updated 28 months ago with non-resolving domain — abandoned or preparatory for handoff.
  • No developer name, no verified publisher, no install count transparency — minimal accountability signals.

Evidence

  • search_provider_override manifest chrome_settings_overrides.search_provider is_default=true pointing to search.web-wise-search.com
  • developer_domain_not_resolving api threat_intel: web-wise-search.com resolves=false; privacy policy fetch failed with ConnectionError
  • privacy_policy_unreachable api privacy_policy_classification.fetched=false reason=fetch_error:ConnectionError — treated as no policy
  • multiple_medium_cves_jquery crx 3 jQuery versions bundled (1.9.1, 1.12.4, 3.3.1); 4 distinct CVE IDs, all medium severity, none at fixed_in version
  • no_csp_with_vulnerable_jquery manifest csp_present=false combined with CVE-laden jQuery < 3.5 triggers v2e jquery+no-CSP amplifier
  • stale_extension store 28 months since last update; domain non-resolving; abandoned or ownership-transfer risk
  • no_developer_name store developer_name empty; no verified publisher badge; no featured badge; unverifiable identity
  • dynamic_script_src crx script_src_dynamic in jquery-1.12.4.min.js — remote script injection surface present

CVE Exposures (10)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@1.12.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.12.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; medium risk on its own but paired with search override.
  • chrome_settings_overrides.search_provider (is_default=true) high Silently replaces default search engine with dev-controlled endpoint; core monetization vector.

Pillar Scores

Permissions4.00
Reputation7.00
Network2.00
Webstore4.00
Maintenance8.50
Privacy10.00
Code Quality3.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 04:37
Listing SHA 75beea9c5606…
Force block — not fired
Score recovered no
Elapsed