Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Smart Auto Refresh

fkjngjgmgbfelejhbjblhjkehchifpcj
Risk Score
5.46
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 100,000
Rating 4.8
Last updated 2024-10-01 (22 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@autorefresh.co
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but admits data collection + third-party sharing without extension-specific scope — scores max privacy risk.
  • jquery@3.4.1 bundled with 2 moderate XSS CVEs (CVE-2020-11022, CVE-2020-11023); no CSP amplifies DOM-XSS risk.
  • scripting + <all_urls>: can inject arbitrary JS into every page; 22-month-old build leaves this surface unpatched.
  • Uninstall and install URL hijacks both trigger (autorefresh.co); collects IP via ip-api.com in js_external_hosts.
  • No developer name on record; stale 22 months with high-capability permissions and no content security policy.

Evidence

  • privacy_policy_admits_collection_and_sharing_no_scope store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D clause → +10.0 privacy.
  • cve_jquery_xss crx jquery@3.4.1 bundled; CVE-2020-11022 + CVE-2020-11023 (moderate); fixed_in 3.5.0 — library below fixed version.
  • no_csp_plus_cve_dom_sink crx csp_present=false AND cve_findings non-empty AND dom_sink_innerhtml_userctrl in jquery.js → FIX B +2.0 code quality.
  • uninstall_and_install_url_hijack crx Both onInstalled→autorefresh.co/ and setUninstallURL→autorefresh.co/uninstall detected.
  • ip_api_external_host crx ip-api.com in js_external_hosts indicates IP geolocation lookup — potential user tracking.
  • stale_22_months_high_perm store 22 months since update; scripting+<all_urls> unpatched; falls in 12-24mo band (+6.0 maintenance).
  • verified_publisher_featured_cap_applies store Verified+featured discounts capped at -1.0 each (0c): monetization concern via ip-api and stale>18mo.
  • no_developer_name store developer_name is empty string; +1.0 reputation penalty applied.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Stores user refresh settings; standard low-risk API.
  • unlimitedStorage low Extended quota for settings; low standalone risk.
  • tabs medium Access to tab URLs and metadata across all open tabs.
  • scripting high Paired with <all_urls> host permission; can inject code into any page.
  • <all_urls> (host_permissions) high Grants scripting and content-script access to every site the user visits.

Pillar Scores

Permissions6.50
Reputation3.50
Network4.50
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:10
Listing SHA 0b533c88c544…
Force block — not fired
Score recovered no
Elapsed