Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Url Shortener

godoifjoiadanijplaghmhgfeffnblib
Risk Score
3.67
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 80,000
Rating 4.8
Last updated 2026-06-03
Manifest version MV3
CSP present ❌ no
Developer support@thebyteseffect.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@3.2.1 carries 3 medium XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP present amplifies risk.
  • No CSP on MV3 extension with 11 external JS hosts; scripting permission can inject into active tab.
  • 11 distinct external host endpoints (bitly, cutt.ly, is.gd, tny.im, etc.); large outbound surface for a URL shortener.
  • Privacy policy discloses third-party data sharing but lacks retention details; scope is extension-specific but incomplete.
  • Developer name field empty; identity relies solely on domain and verified-publisher badge.

Evidence

  • jquery_cve_triple crx jquery@3.2.1 bundled; 3 medium CVEs unfixed (fixed_in 3.5.0); no CSP to mitigate XSS exploitation.
  • no_csp manifest content_security_policy is null on MV3; v2 calibration adds +2.0 Network for MV2 but MV3 has strict default — no extra penalty applied.
  • eleven_external_hosts crx js_external_hosts has 11 distinct registrable domains; >3 threshold triggers +1.5 network penalty.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; reputation discounts applied, floor 2.0.
  • privacy_policy_third_party_sharing api Policy fetched; scope_extension=true, data_collection=true, third_party_sharing=true, retention=false.
  • install_url_hijack crx onInstalled opens thebyteseffect.com page — own domain, not 3rd-party; low additional risk.
  • uninstall_url_hijack crx setUninstallURL points to thebyteseffect.com/posts/uninstall-url-shortner/ — own domain, not 3rd-party.
  • obfuscation_clean crx obfuscation_score=0.0, code_findings_raw empty; no dynamic eval or exfil indicators detected.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • contextMenus low Adds right-click menu; low standalone risk.
  • activeTab low Access to current tab only on user interaction; scoped.
  • storage low Local data persistence; no cross-origin reach.
  • scripting medium Can inject scripts into active tab; limited by activeTab scope.
  • https://tinyurl.com/* low Narrow host permission to one URL-shortener service API endpoint.

Pillar Scores

Permissions1.30
Reputation2.00
Network3.50
Webstore1.00
Maintenance0.00
Privacy2.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA 26f9b8eb70fe…
Force block — not fired
Score recovered no
Elapsed 25.7s