Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Word Counter - counts what you type

hjnjgdaeojdfoajjigipjmdnailbmfje
Risk Score
4.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 7,000
Rating 4.2
Last updated 2022-05-24
Manifest version MV3
CSP present ❌ no
Developer contact@oorjalabs.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned extension (37+ months since last update) with 3 unpatched medium CVEs in bundled jQuery 3.3.1.
  • Content script injected on ALL URLs despite simple word-counter function — broad unnecessary reach.
  • No CSP present; jQuery XSS CVEs combined with no-CSP amplifies exploitation surface on every page.
  • Privacy policy discloses third-party data sharing without scoping specifically to this extension's data.
  • Uninstall URL hijack flag set; destination not captured but warrants inspection.

Evidence

  • stale_extension store Last updated May 2022; ~37 months ago. Maintenance pillar capped at 10.0.
  • cve_jquery_3_3_1 crx 3 medium CVEs in jquery@3.3.1 (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
  • no_csp crx content_security_policy is null (MV3 default enforced, but no explicit hardening; amplifies jQuery CVE risk).
  • content_scripts_all_urls manifest content_scripts_matches includes <all_urls>; over-broad for word-counter category.
  • uninstall_url_hijack crx uninstall_url_hijack == true; target not captured. Webstore +3.0 penalty applied.
  • third_party_sharing_policy store Privacy policy: fetched, scoped, data_collection=true, third_party_sharing=true, retention=true.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied but capped per 0c (stale>18mo + CVEs).
  • js_external_hosts crx 8 external hosts referenced in JS: paypal.com, wordpress.com, c306.net, github.com, etc. (3 countries).

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Stores user preferences/word counts locally; expected for this category.
  • content_scripts:<all_urls> high Content script injected on every site; broad reach for a word-counter, no host restriction.

Pillar Scores

Permissions2.80
Reputation2.00
Network2.50
Webstore4.00
Maintenance10.00
Privacy1.00
Code Quality2.00
CVE Exposure5.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 06:17
Listing SHA 3908822a9aab…
Force block — not fired
Score recovered no
Elapsed 488.0s