Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Google Meet AI Translate

jffmadlbndodbiimdmjhmfcmlcpinkfb
Risk Score
5.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 10,000
Rating 3.4
Last updated 2025-03-10 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer hi@donenote.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: uses 'Google' in name/title without verified ownership of Google brand.
  • Privacy policy on zerocoder.com does not scope to this extension and lacks retention disclosure.
  • Three medium CVEs in bundled jquery@3.3.1 (XSS); no CSP amplifies DOM-sink risk.
  • Extension contacts raw IP (5.44.46.205) and zerocoder.com — 3 external hosts across 3 countries.
  • Developer name absent; policy domain (zerocoder.com) differs from dev domain (donenote.com).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, brands=['google'], confirmed_owner=false; not verified or featured.
  • cve_jquery_3.3.1 crx 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) in inline jquery@3.3.1; fixed_in 3.5.0.
  • no_csp crx content_security_policy is null; MV3 but no explicit CSP declared, amplifying XSS/DOM-sink risk.
  • external_hosts crx js_external_hosts: 5.44.46.205 (raw IP, AE), google.com (US), zerocoder.com (DE) — 3 countries.
  • privacy_policy_scope_mismatch api Policy fetched from zerocoder.com; scope_extension=false, data_collection=false, retention=false.
  • dom_xss_sink crx popup.js assigns innerHTML from variable tempHTML — DOM-XSS sink with no CSP guard.
  • developer_name_missing store developer_name is empty string; email hi@donenote.com but policy hosted on zerocoder.com.
  • months_since_update_15 store Last updated March 2025; 15 months stale — maintenance score 6.0 (12-24mo band).

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • scripting medium Can inject JS into active tab; medium-impact without broad host permissions.
  • activeTab low Transient access to current tab only; low risk in isolation.

Pillar Scores

Permissions1.30
Reputation7.00
Network3.50
Webstore5.50
Maintenance6.00
Privacy9.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:45
Listing SHA 685475aa6fcb…
Force block — not fired
Score recovered no
Elapsed 24.9s