Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Productivity Owl

eoagmdboiealblmpaahjlhajggndaahi
Risk Score
5.05
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 6,000
Rating 4.0
Last updated 2025-08-10 (10 months ago)
Manifest version MV3
CSP present ✅ yes
Developer markrieck81@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy (snipcss.com) explicitly admits data collection and third-party sharing without scoping to this extension — highest privacy risk tier.
  • Three moderate CVEs in bundled jQuery 3.3.1 (XSS); version below fixed_in 3.5.0.
  • Content scripts injected on <all_urls> combined with innerHTML DOM sinks and new Function() constructors create real XSS attack surface.
  • Developer email is free webmail (gmail) with no verified business domain; privacy policy hosted on unrelated third-party domain.
  • Featured badge present but no verified publisher; policy on snipcss.com (unrelated to Productive Mark LLC) undermines accountability.

Evidence

  • privacy_policy_scope_mismatch crx Policy at snipcss.com: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy pillar.
  • cve_jquery_3.3.1 crx 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) in jquery@3.3.1; fixed in 3.5.0.
  • dom_sink_innerhtml_userctrl crx 4 files with innerHTML assignment from variable; CSP present so +0.5 each, but CVEs present → elevated to +2.0 per FIX B.
  • function_constructor crx new Function() found in jquery.qtip.js, jquery.qtip.min.js, mustache.js → +2.5 code quality.
  • content_scripts_all_urls manifest content_scripts matches <all_urls> with no host_permission restriction; broad page-level access.
  • free_webmail_developer store Developer email markrieck81@gmail.com; no business domain; not verified publisher.
  • featured_badge store is_featured_by_google=true → -2.0 reputation discount applied.
  • js_external_hosts crx 12 distinct external JS hosts including scrapehawk.com, snipcss.com, ionden.com; geo diversity IN+US.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Can read tab URLs/titles; productivity extension monitoring tabs is somewhat expected.
  • history medium Access to full browsing history is sensitive; productivity tool may use for tracking.
  • storage low Local data persistence only.
  • unlimitedStorage low Expands storage quota; low direct privacy risk.
  • alarms low Scheduling only, no data access.
  • content_scripts:<all_urls> high Injects scripts on every page; broad DOM access combined with innerHTML sinks raises XSS risk.
  • host_permissions:fonts.googleapis.com low Narrow font CDN access only.

Pillar Scores

Permissions4.00
Reputation6.00
Network2.50
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality5.50
CVE Exposure3.00

Scoring History

v3.6 5.05 Medium review 2026-06-16
v3.4-rev 4.34 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA a13209971b16…
Force block — not fired
Score recovered no
Elapsed 35.1s