Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Popup Blocker for Google Chrome™

ddmhlmdockeihjdpbkcnnfnlcgjhccgk
Risk Score
6.83
Risk Level: High
Recommendation: 🚫 BLOCK
Category Adblock
Installs 20,000
Rating 4.0
Last updated 2022-01-25 (53 months ago)
Manifest version MV3
CSP present ❌ no
Developer keyaan.travis2021@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Google™ brand impersonation by gmail.com developer with no verified business — clear reputation risk.
  • Extension abandoned 53 months ago with 3 unpatched jQuery CVEs (XSS) and no CSP; CVE×1.5 amplifier applies.
  • content_scripts on <all_urls> injects vulnerable jQuery into every page; eval_user_input + innerHTML sink present.
  • Privacy policy is Google's generic account policy — scope_extension=false, admits data collection & 3rd-party sharing.
  • Uninstall URL hijack and install URL hijack flagged; description promises ad-blocking but lacks webRequest/DNR.

Evidence

  • brand_impersonation store Title contains 'Google Chrome™' trademark; brand_mention.is_impersonation=true, confirmed_owner=false, dev=gmail.com.
  • stale_extension store Last updated January 2022; 53 months since update triggers maintenance score 10.0.
  • jquery_cve_triple crx jquery@3.1.1 carries 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP amplifies risk ×1.5.
  • generic_privacy_policy store Privacy policy is myaccount.google.com — scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
  • uninstall_install_hijack crx Both install_url_hijack and uninstall_url_hijack are true; targets null but pattern is monetization shell indicator.
  • content_scripts_all_urls manifest content_scripts_matches=[<all_urls>] injects into every page despite no host_permissions declared.
  • description_mismatch store Promises ad/popup-blocking but lacks declarativeNetRequest or webRequest permission.
  • free_webmail_no_dev_name store developer_email=keyaan.travis2021@gmail.com, developer_name empty; no business identity verifiable.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.1.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • activeTab low Grants access only to active tab on user interaction; limited blast radius.
  • storage low Persists local settings; no cross-origin data risk on its own.
  • contextMenus low Adds right-click menu items; low direct risk.
  • content_scripts:<all_urls> high Injects JS into every page; high reach despite narrow declared permissions.

Pillar Scores

Permissions3.30
Reputation7.50
Network2.00
Webstore8.50
Maintenance10.00
Privacy10.00
Code Quality5.50
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA c66290189d31…
Force block — not fired
Score recovered no
Elapsed 30.5s