Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Crypto Tracker

ebjjekdklfdnkbnjlinganmllmjfdblk
Risk Score
5.17
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 2,000
Rating 3.9
Last updated 2023-09-08 (33 months ago)
Manifest version MV3
CSP present ❌ no
Developer dinhnluong@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jQuery 1.9.1 carries 3 moderate CVEs (XSS); version far below fixed_in 3.5.0, no CSP amplifies risk
  • Privacy policy is Google's generic account policy — scope_extension=false, admits data collection and 3rd-party sharing; scores 10.0
  • Extension last updated 33 months ago; effectively zombie-level staleness with known CVEs
  • Developer is free-webmail (gmail) individual with no verified business; no domain identity
  • No CSP present on MV3 extension bundling vulnerable jQuery with external host access

Evidence

  • jquery_cve crx jquery@1.9.1 bundled in js/bootstrap.min.js; 3 moderate CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in 3.5.0
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — not scoped to this extension
  • stale_extension store Last updated September 2023; 33 months since update — high staleness with unpatched CVEs
  • free_webmail_dev store Developer email dinhnluong@gmail.com; no verified publisher, no business domain
  • no_csp crx content_security_policy is null; no CSP on MV3 extension with vulnerable jQuery and 6 external JS hosts
  • external_hosts crx 6 external JS hosts: api.coincap.io, assets.coincap.io, coinmarketcap.com, getbootstrap.com, github.com, popper.js.org
  • is_featured_by_google store Extension carries Google Featured badge; applied -2.0 to reputation pillar
  • no_bad_hosts api threat_intel bad_host_hits, affiliate_hits, and monetization_hits all empty; no threat-intel flags

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Pillar Scores

Permissions0.00
Reputation6.50
Network3.50
Webstore0.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA 208a5f2bf8f5…
Force block — not fired
Score recovered no
Elapsed 22.6s