Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

BeeLine Reader

ifjafammaookpiajfbedmacfldaiamgg
Risk Score
4.98
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category ReaderMode
Installs 20,000
Rating 3.5
Last updated 2026-01-17 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@beelinereader.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — not scoped to this extension; data collection and 3rd-party sharing admitted without extension-specific disclosure.
  • jquery@3.4.1 bundles two medium CVEs (CVE-2020-11022, CVE-2020-11023) with no CSP, amplifying XSS risk across all sites visited.
  • No CSP declared (MV3); dom_sink_innerhtml_userctrl found in 3 files including readability.js and React DOM, all active on every site.
  • Broad host access *://*/* with scripting permission enables full read/write on all pages; uninstall URL redirects to Google Forms survey.
  • No developer name listed; privacy policy is a generic Google account policy with third_party_sharing=true and no extension scope.

Evidence

  • privacy_policy_generic_google store Privacy URL is myaccount.google.com/privacypolicy — Google's own policy, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • cve_medium_jquery crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (both moderate XSS); fixed_in 3.5.0. No CSP amplifies risk.
  • dom_sink_no_csp crx dom_sink_innerhtml_userctrl in 3 files with csp_present=false triggers elevated code-quality scoring (FIX B).
  • broad_host_scripting manifest host_permissions *://*/* + scripting + content_scripts on http/https://*/* gives full page read/modify on all sites.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target is a Google Forms survey URL — low severity but flagged.
  • no_developer_name store developer_name is empty string; only email contact@beelinereader.com provided. +1.0 reputation.
  • featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount (Featured / follows recommended practices).
  • react_below_16_4_no_csp crx react@16.12.0 bundled (below 16.4 threshold n/a; 16.12>16.4). No CVE amplifier applies for react version. Noted for completeness.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Access to tab URLs/titles; medium risk but standard for reader-mode extensions.
  • storage low Stores user preferences locally; low risk.
  • scripting high Programmatic script injection into pages; high risk when paired with *://*/* host access.
  • *://*/* high Broad host access to all HTTP/HTTPS sites; enables reading/modifying all page content.

Pillar Scores

Permissions5.30
Reputation5.50
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality4.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:42
Listing SHA 3e3b819c3473…
Force block — not fired
Score recovered no
Elapsed 30.6s