Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Popularity Sort for eBay™

gikmaepdichkplhdildclnphgpiaiibf
Risk Score
4.62
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 40,000
Rating 3.7
Last updated 2025-12-07 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer extensions@eladnava.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing (Privacy=10.0).
  • jQuery 1.11.1 bundles 3 medium CVEs (XSS); none fixed below 1.11.1; all unpatched in deployed version.
  • Brand impersonation: eBay™ trademark used in name/title; developer is not a confirmed eBay owner.
  • Content script injected on <all_urls> gives DOM access on every site, amplifying CVE XSS risk.
  • Dynamic <script> creation in jQuery combined with no CSP raises script-injection surface.

Evidence

  • privacy_policy_generic_google store Privacy URL points to myaccount.google.com policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
  • cve_medium_x3_jquery crx jquery@1.11.1 has CVE-2019-11358, CVE-2020-11023, CVE-2015-9251 (all medium). Fixed in 3.5.0; bundled version far below fixed.
  • brand_impersonation_ebay store brand_mention.is_impersonation=true; confirmed_owner=false; eBay trademark used in extension name.
  • content_scripts_all_urls manifest content_scripts_matches=[<all_urls>]; broad DOM injection on every site the user visits.
  • csp_absent_mv3 manifest content_security_policy=null; MV3 provides defaults but no explicit CSP hardening declared.
  • script_src_dynamic_jquery crx jQuery JSONP transport creates dynamic <script> elements; combined with CVE-laden version raises XSS risk.
  • installs_10k_plus store 40,000 installs; moderate blast radius for any supply-chain or XSS exploit via unpatched jQuery.
  • maintenance_3_6mo store Last updated December 7, 2025; 6 months since update → maintenance score 1.5.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.11.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.11.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.11.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Stores extension settings locally; no user data exfiltration risk on its own.
  • content_scripts:<all_urls> high Content script injected on all URLs grants broad DOM read/write across every site visited.

Pillar Scores

Permissions2.50
Reputation6.00
Network0.00
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality3.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:36
Listing SHA d50c80d1f1e4…
Force block — not fired
Score recovered no
Elapsed 26.6s