Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Upvote First for StackOverflow

jafbgebfjkfejghbdeohaadmfghkmjlo
Risk Score
5.50
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 78
Rating 4.2
Last updated 2022-04-26 (50 months ago)
Manifest version MV3
CSP present ❌ no
Developer jossef12@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jQuery 3.1.0 bundles 3 medium CVEs (XSS); no CSP and no update in 50 months amplifies exposure.
  • Privacy policy fetched but scope_extension=false AND data_collection=true AND third_party_sharing=true — admits broad data sharing without scoping to this extension.
  • Developer uses free webmail (gmail) with no verified business domain; brand_mention flags StackOverflow impersonation.
  • Extension abandoned: 50 months since last update with unfixed vulnerable dependency.
  • No content security policy on MV3 extension with externally referenced JS hosts (github.com, jqueryui.com).

Evidence

  • jquery@3.1.0 — 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), fixed in 3.5.0 crx Bundled vulnerable jQuery not updated in 50 months; no CSP amplifies XSS risk per v2 jquery+no-CSP rule.
  • Privacy policy admits data_collection=true + third_party_sharing=true but scope_extension=false store v3.5(D): policy fetched, not scoped to extension, admits collection+3rd-party sharing => +10.0 privacy.
  • Abandoned extension: 50 months since last update store months_since_update=50 exceeds 36-month threshold; zombie booster does not apply (installs<10K).
  • Brand impersonation: StackOverflow mentioned, confirmed_owner=false, dev=gmail store brand_mention.is_impersonation=true, not verified publisher, not featured by Google => +2.0 reputation.
  • Free webmail developer (gmail) with no business domain store jossef12@gmail.com; no developer domain resolved; +1.5 reputation for free-webmail dev.
  • No CSP on MV3 extension with external JS hosts crx csp_present=false; js_external_hosts=[github.com, jqueryui.com]; no MV2+no-CSP network penalty (MV3).
  • is_featured_by_google=true — partial reputation mitigation store Featured badge applied; -2.0 reputation discount but impersonation and gmail dev floor reputation at 7.0.
  • Content scripts scoped to StackExchange network only; no broad host access mismatch crx Permissions match stated function; install_perm_anomaly.small_install_high_perm=false.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.1.0 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.1.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.1.0 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • background low Allows background processing; low risk without high-impact paired permissions.
  • storage low Local data storage only; no exfil risk by itself.
  • host:*.stackoverflow.com + StackExchange network medium Content scripts run on all SE network domains; scoped to stated function but broad within that network.

Pillar Scores

Permissions1.30
Reputation7.00
Network0.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:44
Listing SHA 956b0a4252a3…
Force block — not fired
Score recovered no
Elapsed 29.0s