Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

PerfecTab

eflcledgcbkinocjidjjcakgmeidoann
Risk Score
5.56
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category NewTab
Installs 40,000
Rating
Last updated 2024-05-28 (28 months ago)
Manifest version MV3
CSP present ❌ no
Developer myperfecttab@outlook.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extension is 28 months stale — zombie risk with 40K users on new tab surface.
  • jquery@1.11.2 carries 3 moderate XSS CVEs; no CSP amplifies DOM-XSS risk.
  • 12 external JS hosts including under-cover.info and ressourceapp.com — opaque/suspicious endpoints.
  • New-tab override on 40K installs; every new tab is a high-reach trust boundary.
  • Free-webmail developer email (outlook.com) with no verified publisher badge.

Evidence

  • newtab_override manifest chrome_url_overrides.newtab set — intercepts every new tab for 40K users.
  • stale_extension store 28 months since last update; qualifies for zombie-booster (>24mo + 10K+ installs).
  • jquery_cve crx jquery@1.11.2 with CVE-2019-11358, CVE-2020-11023, CVE-2015-9251 (3x moderate XSS); fixed in 3.5.0.
  • no_csp_plus_cve crx csp_present==false AND 3 moderate CVEs in jquery; dom_sink_innerhtml_userctrl triggers elevated score.
  • suspicious_external_hosts crx under-cover.info and www.ressourceapp.com in js_external_hosts — non-obvious, opaque domains.
  • script_src_dynamic crx Dynamic <script src=> creation in jquery.min.js — remote code loading surface.
  • free_webmail_dev store Developer email myperfecttab@outlook.com; no verified publisher badge.
  • search_engine_count_2 crx NewTab contacts 2 search engines (google.com, yahoo.com) — minor monetization signal.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.11.2 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.11.2 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.11.2 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • geolocation medium Exposes physical location; plausible for weather widget but privacy risk if misused.
  • storage low Local data persistence; standard for NewTab customization.
  • topSites medium Exposes user browsing history summary; standard for NewTab but leakable.
  • chrome_url_overrides.newtab medium Replaces every new tab page — high reach, intercepts user navigation intent.

Pillar Scores

Permissions3.00
Reputation6.50
Network5.50
Webstore5.50
Maintenance8.50
Privacy0.00
Code Quality5.50
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 15:47
Listing SHA 1478ba15e466…
Force block — not fired
Score recovered no
Elapsed