Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Unpaywall

iplffkdpngmdjhlpjmppncnlhomiipha
Risk Score
3.29
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category ReaderMode
Installs 900,000
Rating 4.0
Last updated 2025-01-08 (20 months ago)
Manifest version MV3
CSP present ✅ yes
Developer extension@unpaywall.org
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@3.1.1 bundles 3 moderate CVEs (XSS); unfixed since 2020, fixed_in 3.5.0
  • Privacy policy fetched but scope_extension=false and length=120; too generic to be adequate
  • 17 months since last update; stale for a 900K-install extension with known CVEs
  • Content scripts run on <all_urls> giving broad page-read reach across all sites
  • 5-country JS host diversity (CA/FR/GB/IN/US) slightly elevates network surface

Evidence

  • verified_publisher + featured store Verified publisher badge and Google Featured badge; reputation floor 2.0 applied.
  • jquery@3.1.1 CVEs crx 3 moderate-severity jQuery XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
  • privacy_policy_too_short api Policy length=120 chars, scope_extension=false, data_collection=false; v3 FIX A => +9.0.
  • content_scripts <all_urls> manifest Runs on all pages; function is scholarly article lookup so justified-broad applies partially.
  • stale_update store 17 months since update; maintenance score +6.0 (12-24mo band).
  • no_bad_hosts_no_monetization api threat_intel: bad_host_hits=[], monetization_hits=[], affiliate_hits=[]; clean.
  • obfuscation_score=0_code_findings_empty crx No obfuscation, no suspicious code findings; clean JS scan.
  • host_geo_diversity crx JS hosts span 5 countries (CA,FR,GB,IN,US); academic publishers, not ad-tech.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.1.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Local state only; no cross-origin data access.
  • host_permissions: *://*.oadoi.org/* low Scoped to developer's own API domain; narrow.
  • content_scripts: <all_urls> medium Runs JS on all pages; needed to detect DOIs but broad reach.

Pillar Scores

Permissions1.80
Reputation2.00
Network1.50
Webstore2.00
Maintenance6.00
Privacy9.00
Code Quality1.50
CVE Exposure3.00

Scoring History

sssiedn6f05e74bdp727562726963xsx 3.52 Low review 2026-09-09
sssiedndfdf31abdp727562726963xsx 3.33 Low review 2026-09-07
v3.6 3.29 Low review 2026-06-17

Bookkeeping

Rubric v3.6
Scored at 2026-06-17 08:18
Listing SHA 3b1f74e9429c…
Force block — not fired
Score recovered no
Elapsed