Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SendMe Telegram

ckkfnchnfmgpiejgaacmbngkcjbaaipd
Risk Score
5.21
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 5,000
Rating 4.3
Last updated 2025-04-03 (14 months ago)
Manifest version MV3
CSP present ✅ yes
Developer tonkado@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Telegram brand impersonation by unverified gmail developer; confirmed by brand_mention.is_impersonation.
  • Privacy policy is generic Google account policy — does not scope to this extension, admits data collection and 3rd-party sharing.
  • Content scripts run on all HTTP/HTTPS pages (broad reach) combined with install/uninstall URL hijack signals.
  • jQuery 2.1.4 bundled with 4 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251), none fixed.
  • Developer uses free Gmail address with no verified business domain; uninstall URL hijack flag set.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false; developer domain is gmail.com, not Telegram.
  • generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — +10.0 privacy.
  • content_scripts_broad manifest content_scripts_matches: http://*/* and https://*/* — injects into every page visited.
  • cve_jquery_moderate_x4 crx jquery@2.1.4 has 4 moderate XSS CVEs; all unfixed (fixed_in >= 3.4.0, bundled 2.1.4).
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension sets custom uninstall URL to unknown 3rd-party destination.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens external URL.
  • free_webmail_developer store Developer email tonkado@gmail.com; no verified publisher badge; no business domain.
  • telemetry_google_analytics crx Google Analytics in monetization_hits; only telemetry-tier, no bad hosts detected.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.1.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • activeTab low Access only to currently active tab on user gesture; limited surface.
  • tabs medium Can read tab URLs and titles across all open tabs.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • storage low Local extension data storage only.
  • content_scripts http://*/* https://*/* high Broad content-script injection on all URLs; wide reach even without explicit host_permissions.

Pillar Scores

Permissions4.00
Reputation7.50
Network3.50
Webstore7.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA a7939e9ba91d…
Force block — not fired
Score recovered no
Elapsed 27.4s