Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Quick Find for Google Chrome™

dejblhmebonldngnmeidliaifgiagcjj
Risk Score
4.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 4,000
Rating 4.1
Last updated
Manifest version MV3
CSP present ✅ yes
Developer pdotjs@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: title includes 'Google Chrome™' trademark; developer is unaffiliated gmail user.
  • Privacy policy is Google's generic account policy — not scoped to this extension; data_collection and third_party_sharing both true.
  • Bundled jquery@2.1.1 carries 4 medium CVEs (XSS); not updated to fixed version 3.5.0+.
  • Content scripts inject into all HTTP/HTTPS/FTP pages with no host restriction — full DOM access on every site visited.
  • Developer email is free webmail (gmail.com); no verified publisher badge; update date unknown.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['google']; developer_email=pdotjs@gmail.com; confirmed_owner=false.
  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false; data_collection=true; third_party_sharing=true.
  • cve_jquery_2.1.1 crx jquery@2.1.1 has 4 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); fixed in 3.5.0.
  • broad_content_scripts manifest content_scripts_matches covers ftp://*/* http://*/* https://*/* — DOM access on all sites.
  • free_webmail_developer store developer_email=pdotjs@gmail.com; no business domain; not verified publisher.
  • maintenance_unknown store last_updated is empty string; months_since_update=null; cannot confirm active maintenance.
  • ga_telemetry crx monetization_hits: www.google-analytics.com (telemetry); js_external_hosts also includes github.com, stackoverflow.com.
  • featured_by_google store is_featured_by_google=true; partially mitigates reputation risk but does not override brand-impersonation or privacy gaps.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.1.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • content_scripts: ftp://*/* http://*/* https://*/* high Broad content script injection across all HTTP/HTTPS/FTP pages; reads and manipulates any page DOM.

Pillar Scores

Permissions2.00
Reputation7.50
Network2.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:26
Listing SHA 47caa9115af7…
Force block — not fired
Score recovered no
Elapsed 24.6s