Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

grt memo

hjepgjomhnddghfkpoibmjpofhkbagkm
Risk Score
4.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 80,000
Rating 4.1
Last updated 2025-07-09 (11 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@groundroad.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@2.0.3 bundles 4 moderate CVEs (XSS); fixed versions available up to 3.5.0.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • No CSP present on MV3 extension with known-vulnerable DOM-manipulation library (jquery).
  • Developer name is blank; identity accountability is weak despite verified publisher status.
  • Extension updated 11 months ago; bundled vulnerable jquery not remediated.

Evidence

  • cve_findings_raw: 4 moderate CVEs in jquery@2.0.3 crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; all fixed in >=3.5.0, bundled version 2.0.3.
  • privacy_policy_classification: Google generic policy, not extension-scoped store scope_extension=false, data_collection=true, third_party_sharing=true → scores +10.0 (D rule).
  • csp_present: false on MV3 extension with vulnerable jquery manifest No content_security_policy declared; jquery+no-CSP combo triggers v2e rule.
  • developer_name: empty string store No 'Offered by' name displayed; reduces accountability despite verified_publisher=true.
  • verified_publisher: true; groundroad.com resolves, not throwaway store Verified publisher discount applied but capped at -1.0 due to monetization/stale checks N/A; full -3.0 applied here (no stale/CVE cap trigger on publisher discount per 0c: CVE present caps at -1.0).
  • installs: 80,000 — moderate blast radius store +1.0 webstore for >10K installs.
  • months_since_update: 11 — in 6-12mo band store Maintenance +3.5; vulnerable jquery not updated in ~11 months.
  • js_external_hosts: twitter.com, www.apache.org crx 2 external hosts referenced; no bad-host or monetization hits; network risk low.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.0.3 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.0.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.0.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.0.3 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; moderate info-disclosure risk.
  • unlimitedStorage low Allows storing large data locally; no direct exfil vector.

Pillar Scores

Permissions1.30
Reputation4.00
Network2.00
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:39
Listing SHA 5922744145b2…
Force block — not fired
Score recovered no
Elapsed 28.1s