Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

URL Shortener by Rebrandly

eaidebojanpehpceonghnmgdofblnlae
Risk Score
4.71
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 70,000
Rating 4.3
Last updated 2026-04-22 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer dev@rebrandly.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; not patched.
  • importScripts loads remote Workbox CDN in service worker — remote code execution surface.
  • new Function() constructor executes dynamic string code on window — high code quality risk.
  • Privacy policy admits data collection and 3rd-party sharing but is not scoped to this extension.
  • Content script declared on <all_urls> gives page-level access to every site visited.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed_in 1.12.1 — bundled version not patched.
  • import_scripts_remote crx service-worker.js calls importScripts on https://storage.googleapis.com/workbox-cdn — remote code load.
  • function_constructor crx new Function(T[P])(window) in chunk JS — dynamic code execution on window object.
  • privacy_policy_broad store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — v3.5 D applies → +10.
  • content_script_all_urls manifest content_scripts_matches includes <all_urls>; extension runs on every page.
  • verified_publisher_featured store Extension is verified publisher AND featured by Google; discount applied but capped by monetization/CVE rules.
  • uninstall_url_hijack crx uninstall_url_target=https://rebrandly.live/Uninstall-Extension-Firefox — own domain, not 3rd party.
  • werxltd_external_host crx js_external_hosts includes werxltd.com — third-party domain outside rebrandly namespace; warrants review.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • contextMenus low Used to add right-click shortcut; low standalone risk.
  • identity medium OAuth token access; scoped but enables auth impersonation if abused.
  • activeTab medium Access current tab URL/content on user action; limited to active tab.
  • tabs medium Can read URLs of open tabs; moderate surveillance surface.
  • storage low Local extension data storage; low risk in isolation.
  • clipboardWrite low Copies shortened URL to clipboard; output-only, low risk.
  • scripting medium Can inject scripts; combined with <all_urls> content_script raises risk.
  • content_scripts:<all_urls> high Content script runs on every page via <all_urls> match; broad page access.
  • host_permissions:*://*.rebrandly.com/* low Scoped to own domain; expected for URL shortener service.
  • host_permissions:*://rebrandly.live/* low Secondary own domain; acceptable scope.

Pillar Scores

Permissions3.80
Reputation2.00
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality7.50
CVE Exposure7.00

Scoring History

sssiedn320d0c72dp727562726963xsx 5.07 Medium review 2026-08-30
fsssiedxa sssiedx 4.57 Medium review 2026-08-20
sssieddrubricxsx 4.46 Medium review 2026-08-20
v3.6 4.71 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA 6ddef1fbb3d2…
Force block — not fired
Score recovered no
Elapsed 35.5s