Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Annotate web pages/CONTEXT

emajnoacacifjgmkkmheackniabamonm
Risk Score
3.34
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 1,000
Rating 3.5
Last updated 2025-10-30 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer neuralnetworks2.0@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • content_scripts on <all_urls> with no CSP: JS injected into every page with no sandbox constraint.
  • jquery@3.2.0 carries 3 medium XSS CVEs (fix available at 3.5.0); ×1.5 amplifier applies (no CSP + DOM-manipulation lib).
  • Privacy policy is Google's generic account policy, not scoped to this extension; scores as non-scoped with data collection + 3rd-party sharing admitted.
  • Developer uses free Gmail address with no verifiable business identity.
  • innerHTML sink in content_script.js without CSP guard amplifies XSS risk from bundled vulnerable jQuery.

Evidence

  • content_scripts_matches=<all_urls> manifest Extension injects into every URL visited; high reach.
  • jquery@3.2.0 with 3 medium CVEs crx CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; all fixed in 3.5.0.
  • dom_sink_innerhtml_userctrl + no CSP crx innerHTML in content_script.js with csp_present=false triggers FIX B +2.0.
  • privacy_policy_generic store Google account policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
  • free_webmail_developer store Developer email neuralnetworks2.0@gmail.com; no business domain; +1.5 reputation.
  • no_csp manifest content_security_policy is null on MV3; amplifies CVE risk.
  • rating=3.5 store Below-average rating; rating_count not disclosed.
  • months_since_update=8 store 3-6 month band → maintenance +1.5.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.0 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.0 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata; moderate info exposure.
  • activeTab low Scoped to current tab on user action; limited reach.
  • storage low Local storage for annotations; no remote exfil implied.
  • webNavigation medium Observes navigation events across all tabs; broad passive visibility.
  • unlimitedStorage low Allows large local storage; no direct privacy risk.
  • content_scripts:<all_urls> high Injects JS into every page visited; high reach capability.

Pillar Scores

Permissions3.30
Reputation6.50
Network0.00
Webstore0.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure5.25

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA b43da7922a1a…
Force block — not fired
Score recovered no
Elapsed 53.0s