Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

WhenX: Mark Linkedin Profiles with notes

dgafcidlgmbcehokgdeghmfnbpbfhihh
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 7,000
Rating 4.4
Last updated 2026-04-07 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@whenx.io
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but admits third-party data sharing with no extension-specific scope — privacy pillar maxed at 10.
  • Four medium-severity CVEs in bundled jquery@2.1.4 (XSS); library is well below fixed version 3.5.0.
  • Brand impersonation flag: 'linkedin' mentioned but developer is not a confirmed owner/partner.
  • Sandbox CSP includes unsafe-eval and unsafe-inline on script-src; extension injects scripts into all Google TLDs and LinkedIn.
  • history permission gives full browser history access beyond stated LinkedIn-notes function; scope mismatch signal.

Evidence

  • privacy_policy_no_scope api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case classification under v3.5 rule D.
  • cve_jquery_xss crx jquery@2.1.4 carries CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251 (all moderate); fixed_in 3.5.0.
  • brand_impersonation store brand_mention.is_impersonation=true for 'linkedin'; confirmed_owner=false; developer is not LinkedIn.
  • sandbox_csp_unsafe_eval_inline manifest Sandbox CSP: script-src 'self' 'unsafe-inline' 'unsafe-eval'; elevates XSS risk from CVE-laden jQuery.
  • history_permission manifest history permission declared; broader than needed for a LinkedIn profile annotation tool.
  • connect_src_mixpanel manifest connect-src includes api.mixpanel.com — third-party analytics/telemetry endpoint.
  • content_scripts_all_google_tlds manifest Content scripts injected on all ~200 Google TLDs plus LinkedIn; broad beyond stated LinkedIn function.
  • function_constructor crx new Function() constructor found in scripts/background.js — dynamic code execution risk.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.1.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • tabs medium Can read tab URLs and titles across all open tabs.
  • history medium Can read full browser history — sensitive user data.
  • activeTab low Scoped to user-activated tab only.
  • contextMenus low Adds right-click menu items, low capability.
  • storage low Local/sync extension storage only.
  • scripting medium Can inject JS into pages matching host_permissions.
  • offscreen low Off-screen DOM processing; limited direct risk.
  • *://*.google.com/* high Broad host permission covering all Google domains + content scripts injected.
  • https://*.linkedin.com/* high Full read/write access to LinkedIn; core function but high-value data surface.

Pillar Scores

Permissions5.50
Reputation4.00
Network5.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality3.50
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 06:00
Listing SHA 3e2fb713b0df…
Force block — not fired
Score recovered no
Elapsed 28.9s