Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Synchro: Productivity Manager for Students

gcfbppmhmopmakhclakgnlpobjedkjhe
Risk Score
5.03
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 611
Rating 5.0
Last updated
Manifest version MV3
CSP present ❌ no
Developer ranashreyas@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • 8 moderate CVEs in bundled jquery@1.12.4 and jquery-ui@1.12.1 (all unfixed); XSS risk amplified by absent CSP.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • new Function() constructor in clickout-event.js enables arbitrary code execution from attacker-controlled input.
  • Broad host permissions (*.com / *.edu) paired with DOM-XSS sinks and no CSP increases exploitation blast radius.
  • Developer is gmail-only with no verified identity; no update timestamp available to assess staleness.

Evidence

  • 8 moderate CVEs in jquery@1.12.4 and jquery-ui@1.12.1; none at fixed_in version crx jquery@1.12.4 has CVE-2015-9251/2019-11358/2020-11022/2020-11023; jquery-ui@1.12.1 has CVE-2021-41182/83/84 and CVE-2022-31160.
  • No CSP present (MV3 extension with csp_present=false) manifest content_security_policy is null; amplifies XSS risk from vulnerable jquery libs and innerHTML sink.
  • function_constructor in clickout-event.js crx new Function(e[1]) called with external data — arbitrary code execution vector.
  • Privacy policy is Google generic account policy store URL points to myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • Gmail developer, no verified publisher, no business domain store developer_email=ranashreyas@gmail.com; verified_publisher=false; brand_mention.developer_domain=gmail.com.
  • Broad host permissions beyond stated task-tracker function manifest host_permissions include https://*.com/ and https://*.edu/ — wider than needed for local task management.
  • last_updated missing; maintenance risk unknown api last_updated is empty string; months_since_update null. Maintenance pillar scored conservatively at 6-12mo band.
  • is_featured_by_google=true provides minor trust signal store Google Featured badge reduces reputation risk but does not offset CVE and code-quality findings.

CVE Exposures (8)

CVELibrarySeverity Fixed inSummary
CVE-2021-41182 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-41184 jquery-ui@1.12.1 moderate 1.13.0 XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2022-31160 jquery-ui@1.12.1 moderate 1.13.2 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in
CVE-2021-41183 jquery-ui@1.12.1 moderate 1.13.0 XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2019-11358 jquery@1.12.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.12.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Local data persistence; no cross-origin exfil risk on its own.
  • notifications low Can show desktop alerts; limited abuse surface.
  • https://*.com/ medium Broad host access across all .com sites; wider than needed for a task tracker.
  • https://*.edu/ medium Access to all .edu sites; plausible for student tool but still broad.

Pillar Scores

Permissions2.30
Reputation6.50
Network2.00
Webstore1.00
Maintenance5.00
Privacy10.00
Code Quality5.50
CVE Exposure5.25

Scoring History

v3.6 5.03 Medium review 2026-06-16
v3.4-rev 5.32 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:35
Listing SHA 8232c7b8b763…
Force block — not fired
Score recovered no
Elapsed 38.0s