Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

股票提醒助手

goiffchdhlcehhgdpdbocefkohlhmlom
Risk Score
6.44
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Other
Installs 5,000
Rating 4.6
Last updated 2023-06-21 (38 months ago)
Manifest version MV3
CSP present ✅ yes
Developer v71000@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned 38 months — zombie extension with broad *://*/ host access; prime acquisition/hijack target.
  • jQuery 1.7.1 bundles 5 unpatched XSS CVEs (all medium); version far below fixed_in=3.5.0.
  • Privacy policy is Google's generic account policy — not scoped to this extension; data handling unknown.
  • Free-webmail developer (gmail) with no verifiable business identity; no verified publisher badge.
  • function_constructor + dynamic script creation in bundled jQuery raise code-quality risk under broad host access.

Evidence

  • broad_host_access manifest *://*/ in host_permissions gives access to all URLs despite narrow stated function (stock alerts).
  • zombie_extension store 38 months since last update (June 2023); maintenance pillar maxed at 10 + zombie booster N/A (<10K installs).
  • cve_jquery_1.7.1 crx 5 medium CVEs in bundled jquery@1.7.1; fixed_in ranges 1.9.0–3.5.0; current version dangerously stale.
  • generic_privacy_policy store Privacy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) → +10 privacy.
  • free_webmail_developer store Developer email v71000@gmail.com; no verified publisher; no business domain; reputation floor applies.
  • code_quality_findings crx function_constructor (×2) and script_src_dynamic in jquery bak/min files; dom_sink_innerhtml in active jquery.
  • geo_diversity crx JS external hosts span 4 countries (CA, GB, IE, US); +1.5 network geo-diversity penalty applied.
  • triple_stale_fingerprint crx >24mo stale + CVEs present + MV3 (MV2 penalty N/A); v2 calibration +2.0 webstore triple-stale applied.

CVE Exposures (5)

CVELibrarySeverity Fixed inSummary
CVE-2012-6708 jquery@1.7.1 moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2019-11358 jquery@1.7.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.7.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-7656 jquery@1.7.1 moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2015-9251 jquery@1.7.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Stores user preferences locally; low risk.
  • alarms low Schedules periodic stock price checks; expected for this tool.
  • idle low Detects user idle state; minimal risk.
  • notifications low Sends stock price alerts; core function, low risk.
  • http://finance.sina.com.cn/ medium Specific stock data source; scoped host, acceptable for stated function.
  • https://xueqiu.com/ medium Specific stock data source; scoped host, acceptable for stated function.
  • http://image.sinajs.cn/ medium Image CDN for Sina Finance; scoped, acceptable.
  • https://stock.xueqiu.com/ medium Specific stock API; scoped host, acceptable for stated function.
  • http://qt.gtimg.cn/ medium Tencent stock quote API; scoped, acceptable.
  • *://*/* high Broad host access — covers all URLs despite narrow stated function.

Pillar Scores

Permissions4.50
Reputation6.50
Network3.00
Webstore1.50
Maintenance10.00
Privacy10.00
Code Quality6.00
CVE Exposure5.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:04
Listing SHA 57bbb4ecfa01…
Force block — not fired
Score recovered no
Elapsed