Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MultiCopy Clipboard, Copy & Paste

fahoojlhneomlloahghepkcegggkpahh
Risk Score
3.59
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 10,000
Rating 3.3
Last updated 2026-02-06 (4 months ago)
Manifest version MV3
CSP present ❌ no
Developer sep@sep.dev
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@3.2.0 bundles 3 medium CVEs (XSS); no CSP amplifies risk per v2 calibration.
  • content_scripts on <all_urls> means extension code runs on every page visited.
  • Privacy policy scoped but lacks data retention disclosure and is silent on third-party sharing.
  • install_url_hijack flag set; onInstalled may open third-party URL.
  • Rating 3.3 with 10K installs and no verified publisher badge reduces trust.

Evidence

  • CVE_findings crx 3 medium CVEs in jquery@3.2.0 (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
  • no_csp manifest content_security_policy is null; MV3 default applies but jquery CVEs gain XSS amplification risk.
  • content_scripts_all_urls manifest content_scripts_matches=['<all_urls>']; broad page access for a clipboard tool.
  • install_url_hijack crx install_url_hijack=true; target is null but flag indicates onInstalled opens external URL.
  • privacy_policy_gaps store Policy fetched, scoped, data_collection=true but retention=false and third_party_silence=true.
  • rating_below_average store Rating 3.3; no verified_publisher badge; not sufficient negative reviews flagged.
  • js_external_hosts crx 7 external hosts referenced (bunq.me, github.com, paulirish.com, etc.); 2 countries (IN, US).
  • featured_by_google store is_featured_by_google=true provides partial trust signal offsetting some reputation risk.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.0 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.0 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • activeTab low Scoped to current tab on user gesture; limited blast radius.
  • storage low Stores clipboard items locally; no cross-origin access implied.
  • contextMenus low Adds right-click menu items; benign for clipboard utility.
  • notifications low Desktop notifications only; no data exfil vector.
  • scripting medium Can inject scripts into pages; combined with content_scripts <all_urls> raises reach.
  • content_scripts:<all_urls> medium Runs on every page; exposes clipboard reads across all sites user visits.

Pillar Scores

Permissions3.30
Reputation5.50
Network1.50
Webstore3.50
Maintenance1.50
Privacy2.00
Code Quality3.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:32
Listing SHA 013fbc239ea1…
Force block — not fired
Score recovered no
Elapsed 25.6s