Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Web Developer Form Filler

gbagmkohmhcjgbepncmehejaljoclpil
Risk Score
5.48
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 30,000
Rating 4.3
Last updated 2025-03-14 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer abzubarev@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — does not scope to this extension's data practices at all.
  • Two stale jQuery versions (1.9.1, 1.12.4) bundled with 7 medium-severity XSS CVEs, none patched.
  • Content scripts inject into <all_urls> including file:// — broad DOM access on every site the user visits.
  • Developer uses free Gmail address with no verifiable business identity; no verified-publisher badge.
  • No CSP declared (MV3, but external host www.apache.org referenced); dynamic script creation in bundled jQuery.

Evidence

  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — +10.0 Privacy.
  • cve_moderate_multiple crx 7 CVE entries across jquery@1.9.1 and jquery@1.12.4; >=3 medium CVEs → base +2.0; 4 extra unique IDs → +1.5 extra.
  • cve_jquery_no_csp_amplifier crx No CSP + medium CVEs in jQuery (DOM-manipulation lib) → ×1.5 amplifier on CVE pillar.
  • broad_host_content_scripts manifest content_scripts_matches includes http://*/* https://*/* file:///*, giving DOM access on all pages.
  • free_webmail_developer store developer_email=abzubarev@gmail.com; no verified publisher; no business domain — Reputation +1.5.
  • featured_by_google store is_featured_by_google=true applies -2.0 Reputation discount (follows recommended practices).
  • no_csp_mv3 manifest content_security_policy=null; MV3 default applies but external host www.apache.org in js_external_hosts.
  • maintenance_stale store months_since_update=15; falls in 12-24mo band → +6.0 Maintenance.

CVE Exposures (7)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.12.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.12.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • activeTab medium Grants access to current tab on user action; moderate risk for a form-filler.
  • storage low Local data persistence only; standard and low-risk.
  • <all_urls> (host_permission) high Content scripts inject into every http/https/file URL — broad DOM access on all sites.

Pillar Scores

Permissions4.50
Reputation6.50
Network4.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality4.50
CVE Exposure5.25

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA a7fc333e8df1…
Force block — not fired
Score recovered no
Elapsed 34.4s