Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Weava Highlighter - PDF & Web

cbnaodkpfinfiipjblikofhlhlcickei
Risk Score
5.79
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 200,000
Rating 4.0
Last updated 2024-02-06 (28 months ago)
Manifest version MV3
CSP present ✅ yes
Developer info@weavatools.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host_permissions (http://*/* + https://*/*) with scripting + webRequest on 200K installs — high-value compromise target.
  • Privacy policy fetched but scope_extension==false AND admits data collection + third-party sharing — scores maximum privacy risk.
  • 28 months without update (>24mo band) raises abandonment/supply-chain risk; no changelog visible.
  • function_constructor and innerHTML DOM-sink in contentPage.js/polyfills.js outside of bundled PDF.js library.
  • No developer name listed and unverified publisher despite significant install base.

Evidence

  • broad_host_permissions manifest http://*/* and https://*/* grant access to all web content; paired with scripting and webRequest.
  • privacy_policy_generic api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 (v3.5-D).
  • stale_extension store Last updated Feb 2024; 28 months since update — 24-36mo band (+8.5 maintenance).
  • code_function_constructor crx new Function() found in contentPage.js and multiple PDF.js assets; +2.5 from function_constructor signal.
  • dom_xss_sink crx innerHTML assignment in polyfills.js; CSP present so +0.5 applied, not elevated.
  • no_developer_name store developer_name is empty string; +1.0 reputation penalty.
  • featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied.
  • no_cve_findings crx cve_findings_raw empty; CVE pillar = 0.0.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; minimal risk.
  • declarativeNetRequest medium Can modify/block network requests; medium risk without host access alone.
  • scripting high Paired with broad host_permissions; can inject JS into any page.
  • storage low Local data persistence; low risk on its own.
  • tabs medium Can read tab URLs and titles across all tabs.
  • unlimitedStorage low Allows large local storage; no direct data-exfil risk.
  • webNavigation medium Observes navigation events across all URLs; privacy surface.
  • webRequest high Can observe all HTTP requests across all URLs given broad host_permissions.
  • notifications low Shows desktop notifications; low standalone risk.
  • host_permissions: http://*/* + https://*/* high Broad host access across all websites; amplifies scripting and webRequest.

Pillar Scores

Permissions6.50
Reputation5.50
Network2.00
Webstore3.00
Maintenance8.50
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA b09b4bc62e2f…
Force block — not fired
Score recovered no
Elapsed 32.1s