Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Equatio - Math made digital

hjngolefdpdnooamgdldlkjgmdcmcjnc
Risk Score
4.59
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Accessibility
Installs 1,000,000
Rating 3.9
Last updated 2026-04-09 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer info@texthelp.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • script_src_dynamic in multiple bundles: dynamic script injection across all_urls is a high-impact XSS vector.
  • new Function() with DOM attribute input in mmlWorker/bundle.js — potential arbitrary code execution from page content.
  • scripting + <all_urls>: broad programmatic script injection on every site the user visits.
  • identity.email permission collects user PII (email); combined with broad host access raises exfil concern.

Evidence

  • privacy_policy_generic store Privacy URL points to Google's own account policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not extension-specific.
  • script_src_dynamic_multiple_files crx Dynamic <script> element creation found in calculator/bundle.js, mathDiscoverGSuiteBundle.js, mathDiscoverabilityBundle.js, formBundle.js, mathjaxFrame/bundle.js.
  • function_constructor_dom_attr crx new Function('item', e.getAttribute('jsTest')) in mmlWorker/bundle.js — executes DOM attribute as code.
  • dom_innerHTML_sink crx innerHTML from variable in browserAction/bundle.js, htmlEditorApi.js, content/6067.js, mathjaxFrame/bundle.js — DOM-XSS sinks.
  • broad_host_scripting manifest host_permissions=<all_urls> + scripting permission + content_scripts on <all_urls>; justified for Accessibility but high capability.
  • is_featured_by_google store Google Featured badge present; reduces reputation risk but does not override code/privacy concerns.
  • cve_findings_empty crx No CVEs detected in bundled libraries (jquery 3.5.1/3.6.0/3.7.1, react 16.13.1/17.0.2). CVE pillar = 0.
  • sandbox_csp_unsafe_eval manifest sandbox CSP includes 'unsafe-eval' — eval permitted inside sandboxed frames, raises risk when combined with dynamic script loading.

Permissions Breakdown

  • activeTab low Grants access to active tab on user action; scoped and low risk.
  • tabs medium Can read tab URLs and metadata across sessions.
  • alarms low Schedules background tasks; no data access.
  • storage low Local/sync storage; no exfil risk alone.
  • identity medium OAuth token access; can retrieve user identity tokens.
  • identity.email medium Explicitly requests user email via OAuth — PII exposure.
  • gcm low Push messaging; low direct risk but enables remote triggering.
  • scripting high Programmatic script injection into pages; HIGH risk with <all_urls>.
  • <all_urls> (host_permissions) high Broad host access across all sites; paired with scripting amplifies risk.

Pillar Scores

Permissions5.50
Reputation3.50
Network3.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality8.00
CVE Exposure0.00

Scoring History

xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 4.77 Medium review 2026-08-13
&#x27;fsssiedxa sssiedx 4.68 Medium review 2026-08-13
fsssiedxa$"sssiedx 4.66 Medium review 2026-08-13
<fsssiedxa"sssiedx 4.86 Medium review 2026-08-13
<fsssiedxa$"sssiedx 4.74 Medium review 2026-08-13
<fsssiedx{"sssiedx 5.06 Medium review 2026-08-02
<fsssiedx{$"sssiedx 5.22 Medium review 2026-08-02
xx pfsssiedxwfdsaxax><!--></ScRiPt>asddsssiedx 4.68 Medium review 2026-08-02
%27fsssiedxw"sssiedx 5.18 Medium review 2026-08-02
4.64 Medium review 2026-08-02
&#x22;fsssiedxwfdsaxax><!--></ScRiPt>asddsssiedx 5.05 Medium review 2026-08-02
$"fsssiedxwsssiedx 4.79 Medium review 2026-08-02
<fsssiedxhfdsaxax><!--></ScRiPt>asddsssiedx 4.83 Medium review 2026-08-02
fsssiedx<sssiedx 4.70 Medium review 2026-08-02
'fsssiedxasssiedx 4.14 Medium review 2026-07-28
fsssiedxa<sssiedx 4.55 Medium review 2026-07-28
<fsssiedxh xx psssiedx 4.73 Medium review 2026-07-28
<fsssiedxh$"sssiedx 4.31 Medium review 2026-07-28
fsssiedxc"sssiedx 4.49 Medium review 2026-07-28
sssieddrubricxsx 4.10 Medium review 2026-07-28
v3.6 4.59 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 04:45
Listing SHA f4b96233672e…
Force block — not fired
Score recovered no
Elapsed