Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Image Downloader - Save pictures

daeljdgmllhgmbdkpgnaojldjkdgkbjg
Risk Score
3.02
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category MediaDownloader
Installs 300,000
Rating 4.6
Last updated 2026-06-01
Manifest version MV3
CSP present ❌ no
Developer porterlarsgren@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest + <all_urls>: extension can observe all HTTP/S requests across every site visited.
  • jquery@3.1.1 bundles 3 medium-severity XSS CVEs; no CSP to mitigate exploitation surface.
  • Free-webmail developer (Gmail) with no verified business identity raises accountability gap.
  • Privacy policy discloses third-party data sharing without scoping retention, reducing trust.
  • External JS host (jqueryui.com) loaded at runtime; no CSP to restrict script sources.

Evidence

  • broad_host_permissions manifest host_permissions includes http://*/*, https://*/*, <all_urls> — full cross-site reach for webRequest and scripting.
  • jquery_cve_bundle crx jquery@3.1.1 bundled (js/libs/jquery-3.1.1.min.js); 3 medium CVEs unfixed below 3.5.0.
  • no_csp manifest content_security_policy is null on MV3; no script-src restriction mitigating CVE-exposed jQuery.
  • external_js_host crx js_external_hosts contains jqueryui.com; remote script dependency with no CSP pin.
  • free_webmail_dev store developer_email is porterlarsgren@gmail.com; no business domain verified.
  • privacy_policy_gaps api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; partially offsets reputation risk.
  • webRequest_permission manifest webRequest declared alongside <all_urls>; can inspect all network traffic passively.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.1.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Saves user preferences; minimal risk.
  • activeTab medium Accesses current tab on user action; scoped but enables page reading.
  • scripting medium Can inject scripts into pages; required for image detection but capable of abuse.
  • downloads medium Core function for image saving; can write to user filesystem.
  • webRequest high Observes all HTTP requests across all URLs; high surveillance capability.
  • declarativeNetRequest medium Can block/redirect network requests declaratively; lower risk than webRequestBlocking.
  • http://*/* high Broad host access across all HTTP sites amplifies webRequest and scripting risk.
  • https://*/* high Broad host access across all HTTPS sites; paired with webRequest raises risk.
  • <all_urls> high Explicit all-URLs host permission; maximizes reach of every capability.

Pillar Scores

Permissions4.50
Reputation3.50
Network2.00
Webstore2.50
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:25
Listing SHA 20d5af8cbb73…
Force block — not fired
Score recovered no
Elapsed 26.8s