Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Firelinks URL Shortner

epdgnnildheopikdpdooanjlafgndmmk
Risk Score
5.30
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 20,000
Rating 4.6
Last updated 2024-11-27 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@firelinks.io
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but has no extension scope, admits data collection and 3rd-party sharing — scores maximum privacy risk.
  • jQuery 1.9.1 bundled with 3 moderate CVEs (XSS); version is far below fixed_in 3.5.0 and no CSP is present.
  • No Content Security Policy (MV3, so no v2 penalty, but amplifies CVE/DOM risk).
  • 12 external JS hosts referenced with no CSP; source files reference remabledesigns.com and jpillora.com among others.
  • Extension last updated 19 months ago; stale maintenance window allows CVE exposure to persist.

Evidence

  • privacy_policy_generic_with_sharing api Policy fetched (tiny.cc redirect); scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (D rule).
  • jquery_cve_triple_moderate crx jquery@1.9.1 carries CVE-2015-9251, CVE-2019-11358, CVE-2020-11023; all unfixed in bundled version.
  • no_csp manifest content_security_policy is null; MV3 default CSP applies but no explicit policy tightening.
  • external_hosts_12 crx 12 external JS hosts in source including remabledesigns.com, jpillora.com, popper.js.org — >3 distinct domains.
  • stale_19mo store Last updated November 2024; 19 months since update → maintenance +6.0 band.
  • featured_by_google store is_featured_by_google=true applies -2.0 reputation discount.
  • developer_name_abbreviated store Developer name is 'VD' — abbreviated, low-accountability signal; email on firelinks.io domain partially offsets.
  • obfuscation_none_code_clean crx obfuscation_score=0.0, code_findings_raw empty; no active malicious code detected.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • activeTab low Scoped to current tab on user action only; limited reach.
  • contextMenus low Adds right-click menu item; no data access on its own.
  • unlimitedStorage low Allows large local storage use; no exfil risk alone.
  • storage low Local extension data persistence; standard use.
  • alarms low Scheduled background tasks; low abuse potential.
  • scripting medium Can inject scripts into active tab; elevated risk without broad host perms.

Pillar Scores

Permissions2.30
Reputation5.50
Network4.50
Webstore1.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA 109554689d27…
Force block — not fired
Score recovered no
Elapsed 27.5s