Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Screenshot Tool - Screen Capture & Editor

edlifbnjlicfpckhgjhflgkeeibhhcii
Risk Score
4.92
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Screenshot
Installs 1,000,000
Rating 4.7
Last updated 2025-01-29 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer gisstapa@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@3.2.1 bundles 3 unpatched medium CVEs (XSS); library below fixed_in 3.5.0 with no CSP amplifies risk.
  • scripting + <all_urls> host permission enables arbitrary JS injection on every visited page.
  • Gmail-only developer identity (no dev name, free webmail) reduces accountability.
  • Privacy policy discloses third-party sharing but omits retention; screenshot tool with broad host access is high-impact.
  • 17 months since last update; CVEs and stale code compound under v3.5 invariant 0c cap.

Evidence

  • host_permissions_all_urls + scripting manifest Extension declares <all_urls> host_permissions and scripting; content scripts also match <all_urls>.
  • cve_jquery_3_medium_x3 crx jquery@3.2.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); all fixed above 3.5.0.
  • no_csp crx content_security_policy is null; MV3 default applies but CVE amplifier triggers (jquery DOM-manip lib + medium CVEs).
  • function_constructor_usage crx new Function() found in js/editor.js and js/lib/fabric.js; dynamic code execution risk.
  • developer_identity store developer_name empty; developer_email is free webmail (gisstapa@gmail.com); no business domain verifiable.
  • verified_publisher + featured store verified_publisher=true and is_featured_by_google=true; discounts applied but capped per 0c (months_since_update=17).
  • privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • description_promise_mismatch store Description promises recording but extension lacks tabCapture/desktopCapture permissions.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Local key-value store; low impact on its own.
  • unlimitedStorage low Extends storage quota; no cross-origin access.
  • scripting high Programmatic script injection into pages; paired with <all_urls> host permission.
  • <all_urls> (host_permissions) high Grants content script + scripting access to every URL the user visits.
  • <all_urls> (content_scripts) high Content script injected on every page; broad data-read surface.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.00
Webstore3.50
Maintenance6.00
Privacy2.00
Code Quality4.50
CVE Exposure5.00

Scoring History

<fsssiedxa$'sssiedx 4.25 Medium review 2026-08-13
<fsssiedxa&#x27;sssiedx 4.22 Medium review 2026-08-13
<fsssiedxa$"sssiedx 4.36 Medium review 2026-08-13
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.51 Medium review 2026-08-13
<fsssiedxa 4.32 Medium review 2026-08-13
fsssiedxa<sssiedx 4.20 Medium review 2026-08-13
%22fsssiedxi$'sssiedx 4.43 Medium review 2026-08-04
4.27 Medium review 2026-08-04
<fsssiedxi&#x22;sssiedx 3.79 Low review 2026-08-04
<fsssiedxf"sssiedx 4.14 Medium review 2026-08-04
<fsssiedxa xx psssiedx 4.43 Medium review 2026-08-04
<fsssiedxi sssiedx 4.36 Medium review 2026-08-04
fsssiedx<sssiedx 4.17 Medium review 2026-08-04
fsssiedxasssiedx 4.43 Medium review 2026-07-28
fsssiedxa'sssiedx 4.57 Medium review 2026-07-28
fsssiedxa 4.15 Medium review 2026-07-28
sssieddrubricxsx 4.16 Medium review 2026-07-28
v3.6 4.92 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA 22a38b9aa6df…
Force block — not fired
Score recovered no
Elapsed 29.7s