Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dynu Dynamic DNS Client

gfjkkccgjogpdhmhdinjngakpajljhba
Risk Score
5.33
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 4,000
Rating 4.9
Last updated 2023-12-29 (30 months ago)
Manifest version MV3
CSP present ❌ no
Developer service@dynu.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and third-party sharing.
  • 6 medium-severity jQuery CVEs (two versions: 1.9.1 and 3.2.1), neither patched to fixed_in version; no CSP amplifies XSS risk.
  • Extension not updated in ~30 months; stale alongside unfixed CVEs is a compound risk.
  • No developer name listed; dev identity relies solely on email domain dynu.com.
  • External hosts include getbootstrap.com, github.com, tether.io — non-developer-owned domains loaded without CSP.

Evidence

  • privacy_policy_generic store Policy URL is Google account privacy policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.0.
  • cve_multiple_medium crx jquery@1.9.1 (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023) and jquery@3.2.1 (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); none at fixed_in.
  • no_csp crx content_security_policy is null; MV3 has strict default but jquery CVEs in DOM-manipulation lib amplify CVE pillar ×1.5.
  • stale_extension store Last updated December 2023; months_since_update=30 → Maintenance +8.5.
  • no_developer_name store developer_name is empty string; Reputation +1.0.
  • external_hosts_non_dev crx js_external_hosts includes getbootstrap.com, github.com, tether.io — 3+ distinct non-dev domains → Network +1.5.
  • install_url_hijack crx install_url_hijack=true but target is internal options.html, not a third-party URL — Webstore onInstalled penalty not applied.
  • operator_cluster_clean api sibling_count=0; no bad_host_hits, affiliate_hits, or monetization_hits; domain resolves, not throwaway.

CVE Exposures (6)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • alarms low Schedules periodic DNS update checks; low risk.
  • background low Keeps service worker alive for periodic updates; expected for DDNS client.
  • notifications low Alerts user to IP change/update status; low abuse potential.
  • storage low Stores credentials/settings locally; low risk.
  • https://api.dynu.com/ low Scoped to developer-owned API endpoint; matches stated function.
  • http://ipcheck.dynu.com/ipcheck.asp low Scoped to developer-owned IP-check endpoint; matches stated function.
  • http://ipcheckv6.dynu.com/ipcheck.asp low Scoped to developer-owned IPv6 IP-check endpoint; matches stated function.

Pillar Scores

Permissions1.20
Reputation5.50
Network2.50
Webstore3.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure5.25

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA ccc089acb0e2…
Force block — not fired
Score recovered no
Elapsed 30.3s