Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

ショッピングリサーチャー

imcmhieloonofimeilceagabgdnhnlee
Risk Score
4.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 60,000
Rating 4.5
Last updated 2025-05-25 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer cs-info@re-mine.jp
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@2.1.4 bundles 4 medium CVEs (XSS) with no CSP, amplifying DOM-manipulation risk on 24 marketplace origins.
  • Privacy policy hosted on sedo-logi.com (different domain from re-mine.jp), not scoped to this extension; data collection status unclear.
  • install_url_hijack flag set true; onInstalled may open third-party URL — verify destination.
  • Affiliate hits to Rakuten network (3 domains) confirm monetization shape; category is Shopping so partially expected but warrants review.
  • No developer name listed; 13 months since last update on extension with 60K installs increases supply-chain risk window.

Evidence

  • CVE exposure crx jquery@2.1.4 has 4 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); all fixed in >=3.4.0.
  • No CSP + vulnerable jQuery manifest content_security_policy is null; jquery@<3.5 + no CSP triggers v2 +2.0 code quality and CVE amplifier x1.5.
  • Privacy policy off-domain and unscoped store Policy at sedo-logi.com; scope_extension=false, data_collection=false, third_party_silence=true => +9.0 privacy + +1.0.
  • Affiliate network hits crx 3 Rakuten affiliate domains in threat_intel.affiliate_hits; category Shopping partially explains, but 2+ distinct domains => +2.5 webstore.
  • install_url_hijack crx install_url_hijack=true, target=null. onInstalled opens external URL; destination unconfirmed => +2.0 webstore.
  • 12 external JS hosts crx js_external_hosts has 12 entries including wzrd.in, zenorocha.github.io, shopping-researcher.appspot.com => >3 distinct domains.
  • Verified publisher store verified_publisher=true; discount capped at -1.0 due to monetization_hits/affiliate hits (v3.5 invariant 0c).
  • Maintenance stale store 13 months since update => +6.0 maintenance pillar (6-24mo band).

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.1.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • storage low Local data persistence only; low risk.
  • host_permissions (24 shopping/marketplace origins) medium Content scripts on major JP/US marketplaces; scoped to stated Shopping function.

Pillar Scores

Permissions3.00
Reputation4.50
Network3.50
Webstore5.50
Maintenance6.00
Privacy9.00
Code Quality2.00
CVE Exposure4.50

Scoring History

v3.6 4.74 Medium review 2026-06-16
v3.4-rev 2.59 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA aca64b781a2a…
Force block — not fired
Score recovered no
Elapsed 30.1s