Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Web Paint Tool - draw online

iklgljbighkgbjoecoddejooldolenbj
Risk Score
2.19
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Screenshot
Installs 100,000
Rating 4.5
Last updated 2026-08-24
Manifest version MV3
CSP present ✅ yes
Developer ludwigbarbara144@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@3.2.1 bundles 3 moderate CVEs (XSS); not patched to fixed_in >= 3.5.0.
  • Developer uses free Gmail; no developer name listed; identity unverifiable.
  • Broad host access (<all_urls>) + scripting allows content injection on every site.
  • Privacy policy scoped but lacks retention disclosure and third-party sharing clarity.
  • v2 calibration: verified+featured but Gmail dev email limits reputation discount.

Evidence

  • verified_publisher + featured store Extension holds verified publisher and featured badges; discounts applied but capped by Gmail dev email.
  • developer_email_free_webmail store ludwigbarbara144@gmail.com — free Gmail account; no verified business domain.
  • cve_jquery_moderate_x3 crx jquery@3.2.1 vulnerable to CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; fixed in 3.5.0.
  • host_permissions_all_urls manifest <all_urls> host permission with scripting; justified for drawing-on-page category but high reach.
  • csp_strict manifest CSP: script-src 'self'; object-src 'self' — no unsafe-eval, no remote CDN.
  • privacy_policy_no_retention api Policy scoped to extension, discloses data collection, but retention period not stated.
  • code_quality_clean crx No obfuscation (score 0.0), no code_findings_raw hits, 5 JS files scanned.
  • threat_intel_clean api No bad_host_hits, monetization_hits, affiliate_hits; single geo (US); 0 operator siblings.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • alarms low Scheduling only; no data access risk.
  • scripting medium Can inject scripts into pages; paired with <all_urls> raises capability.
  • storage low Local extension storage; limited risk.
  • <all_urls> (host_permissions) high Broad host access; scripting can operate on every site the user visits.
  • <all_urls> (content_scripts) high Content scripts injected on all URLs; same surface as host_permissions—anti-double-count applied.

Pillar Scores

Permissions3.50
Reputation3.50
Network0.00
Webstore1.00
Maintenance0.00
Privacy2.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:54
Listing SHA 71106e398cb9…
Force block — not fired
Score recovered no
Elapsed