Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Email Extractor

jdianbbpnakhcmfkcckaboohfgnngfcc
Risk Score
4.69
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 400,000
Rating 4.7
Last updated 2025-11-27 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@email-extractor.io
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy (not scoped to this extension), yet admits data collection and 3rd-party sharing — highest privacy risk tier.
  • Content script runs on <all_urls> including mail.google.com and LinkedIn; cookies permission creates exfil surface for harvested emails.
  • Install-URL hijack opens manycontacts.com on install; uninstall-URL hijack to extractor.dev — both monetization/tracking redirects.
  • Bundled jQuery 3.1.1 has three moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP present amplifies risk.
  • 12 external JS hosts including personal/unrecognised domains (altkie.com, carlosmdh.es, horsetelex.com); geo-diversity across 4 countries adds supply-chain risk.

Evidence

  • privacy_policy_generic_google store Privacy policy URL is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • install_url_hijack crx onInstalled opens https://www.manycontacts.com — 3rd-party monetization target.
  • uninstall_url_hijack crx setUninstallURL points to https://extractor.dev/email-extractor/uninstall.html — 3rd-party tracking.
  • cve_jquery_3.1.1 crx jQuery 3.1.1 carries 3 moderate XSS CVEs; fixed_in 3.5.0; no CSP present — v2e amplifier applies.
  • content_scripts_all_urls_plus_cookies manifest content_scripts on <all_urls> + cookies permission = full-page read + cookie access on every site.
  • external_host_diversity crx 12 external JS hosts across 4 countries (CA,DE,IN,US); includes altkie.com, carlosmdh.es, horsetelex.com — unrecognised domains.
  • code_function_constructor crx new Function() in scripts/gmail.js; dynamic script creation in jquery_1_11_2.min.js.
  • featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount but does not override privacy or CVE findings.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.1.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Standard local data persistence; low risk alone.
  • tabs medium Access to tab URLs/titles; moderate risk, paired with content_scripts on <all_urls>.
  • webNavigation medium Can observe all navigation events across all sites.
  • cookies high Read/write cookies; combined with <all_urls> content scripts raises exfil risk.
  • alarms low Scheduling only; minimal direct risk.
  • <all_urls> (content_scripts) high Content script injected on every URL; broad reach enables data harvesting at scale.

Pillar Scores

Permissions6.50
Reputation4.00
Network4.50
Webstore6.50
Maintenance1.50
Privacy10.00
Code Quality5.50
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA a5d63ba556eb…
Force block — not fired
Score recovered no
Elapsed 31.5s