Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shopify Export Data

fmmnkjgilfmnebabogknkkpmopglecgl
Risk Score
5.14
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 5,000
Rating 4.6
Last updated 2026-04-10 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer jaron.smith2006@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Shopify brand impersonation by unverified free-webmail developer (jaron.smith2006@gmail.com).
  • Privacy policy fetched but admits data collection + third-party sharing without extension-specific scope — worst case per v3.5 rule D.
  • jQuery 2.2.4 bundles 4 moderate CVEs (XSS); no CSP amplifies DOM-sink risk across broad content-script injection.
  • Content scripts injected on ALL HTTP/HTTPS pages combined with cookies permission creates wide exfiltration surface.
  • 12 external JS hosts referenced; geo-diversity across 4 countries (CA, FR, IN, US) raises supply-chain concern.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands_mentioned=['shopify'], developer_domain=gmail.com, confirmed_owner=false.
  • privacy_policy_admits_collection_and_sharing_without_scope api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 rule D → +10.0.
  • jquery_cves_no_csp crx jquery@2.2.4 bundles CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251 (all moderate). No CSP. v2e amplifier applies.
  • content_scripts_all_urls manifest content_scripts_matches=['http://*/*','https://*/*'] + cookies permission = broad session-access on every site.
  • dom_sink_innerhtml_no_csp crx dom_sink_innerhtml_userctrl in 3 files (jquery, productlist.js, script.js); csp_present=false elevates each to +2.0.
  • uninstall_url_hijack crx uninstall_url_hijack=true; extension sets uninstall URL to undisclosed third party.
  • free_webmail_no_dev_name store developer_name='', developer_email='jaron.smith2006@gmail.com' — no accountable business identity.
  • geo_diversity api JS hosts span 4 countries (CA, FR, IN, US); 12 external domains referenced in CSP/operator fingerprint.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.2.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.2.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.2.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • tabs medium Allows reading tab URLs and titles; moderate info-disclosure risk.
  • storage low Local data persistence; low risk on its own.
  • cookies high Can read/write cookies including auth tokens on in-scope hosts.
  • host: https://shopify-export.extfy.com/* medium Scoped to single dev-controlled endpoint; acceptable but warrants monitoring.
  • content_scripts: http://*/* https://*/* high Injects JS into every page the user visits — broad DOM access combined with cookies is high-risk.

Pillar Scores

Permissions6.50
Reputation7.50
Network5.50
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure5.25

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA 257e8171150e…
Force block — not fired
Score recovered no
Elapsed 34.5s