Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Recipes Stash

jepcdjidlnpjfdblhhkkfhgbgdgphile
Risk Score
4.74
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 9,000
Rating
Last updated 2024-10-31 (22 months ago)
Manifest version MV3
CSP present ❌ no
Developer nicks@worthathousandwords.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension — generic policy with full disclosure gap.
  • Default search provider override silently redirects all browser searches through recipesstash.com, capturing query data.
  • Bundled jquery@3.3.1 has 3 medium XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023), no CSP present to mitigate.
  • No developer name listed; 22 months since last update raises abandonment and supply-chain risk.
  • MV3 + no CSP with vulnerable jQuery in popup context increases DOM-XSS exploitability.

Evidence

  • search_provider_override manifest chrome_settings_overrides sets recipesstash.com as default search (is_default=true); all queries routed there.
  • privacy_policy_generic_with_third_party_sharing crx Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
  • jquery_cve_medium_x3 crx jquery@3.3.1 in popup/jquery.min.js has 3 medium CVEs; fixed_in 3.5.0. No CSP to block exploitation.
  • no_csp manifest content_security_policy is null; csp_present=false. v2b: MV3 strict default applies, no additional penalty.
  • stale_extension store 22 months since update (6-24mo band); +6.0 maintenance. No changelog visible.
  • no_developer_name store developer_name is empty string; identity accountability reduced. +1.0 reputation.
  • triple_stale_fingerprint store >18mo stale + CVEs present + MV3 (not MV2 so v2c MV2 requirement not met; no additional +2.0 applied).
  • obfuscation_clean crx obfuscation_score=0.0, code_findings_raw empty; no malicious JS patterns detected.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • search medium Allows overriding search provider; paired with chrome_settings_overrides to set default search.
  • host_permissions: https://recipesstash.com/* low Scoped to single developer-controlled domain only.
  • chrome_settings_overrides.search_provider (is_default=true) medium Sets recipesstash.com as default search engine silently; monetization risk via search query capture.

Pillar Scores

Permissions3.00
Reputation6.50
Network0.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:21
Listing SHA 058a4b8b6a99…
Force block — not fired
Score recovered no
Elapsed