Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Comunidade ZDG FREE

iofcjnefopghplghojjpglnjakejkein
Risk Score
6.27
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 10,000
Rating 3.1
Last updated 2026-06-06 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer zapdasgalaxias@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • browsingData + scripting + <all_urls>: can delete user data and inject JS into every site visited.
  • 3 medium CVEs in jquery@3.3.1 (XSS); no CSP present, amplifying DOM-XSS risk across 9 innerHTML sinks.
  • Privacy policy is Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Free-webmail dev (zapdasgalaxias@gmail.com), no verified publisher, low rating 3.1; high-permission extension from unaccountable developer.
  • 12 external JS hosts including raw.githubusercontent.com and third-party payment/analytics endpoints with no CSP guard.

Evidence

  • broad_host_plus_scripting_browsingData manifest http://*/* + https://*/* with scripting and browsingData: can inject code and delete browsing data on any site.
  • privacy_policy_generic_google store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — maps to +10 privacy score.
  • jquery_cve_no_csp crx jquery@3.3.1 has 3 medium CVEs (XSS); no CSP present triggers v2 jquery@<3.5+no_CSP amplifier.
  • innerHTML_sinks_multiple crx 9 files with dom_sink_innerhtml_userctrl; no CSP and CVEs present → each sink scores +2.0 (capped at 4.5 code quality).
  • free_webmail_developer store Developer email zapdasgalaxias@gmail.com; no verified publisher badge, no featured badge, no business website.
  • install_url_hijack manifest onInstalled opens https://web.whatsapp.com/ — install URL hijack to third-party site (+2.0 webstore).
  • external_hosts_12 crx 12 distinct external JS hosts including raw.githubusercontent.com, payfast.greenn.com.br, davealger.info, darkwavetech.com.
  • monetization_telemetry api google-analytics.com in monetization_hits; telemetry-tier only, category not adblock/shopping — +1.0 webstore.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • scripting high Arbitrary JS injection into pages; paired with <all_urls> host access = critical reach.
  • declarativeNetRequest medium Can block/redirect network requests; moderate risk without redirect evidence.
  • browsingData high Can delete cookies, history, cache — serious data destruction capability.
  • activeTab low Scoped to user-activated tab; low risk in isolation.
  • storage low Local extension storage; low risk.
  • http://*/* high Broad host access over all HTTP sites; amplifies scripting and browsingData.
  • https://*/* high Broad host access over all HTTPS sites; amplifies scripting and browsingData.

Pillar Scores

Permissions8.50
Reputation7.50
Network5.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:50
Listing SHA 4afc4b4abc44…
Force block — not fired
Score recovered no
Elapsed