Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

KUARIO Print Anonymous

jhndfihagmlkccghdpjbhebhlnkmnioa
Risk Score
3.76
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs
Rating
Last updated 2025-07-31 (11 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@kuario.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but lacks extension scope and admits third-party data sharing — privacy pillar maxed.
  • jQuery 3.4.1 bundles two medium CVEs (CVE-2020-11022, CVE-2020-11023); no CSP amplifies XSS risk.
  • No content security policy (MV3 default strict but null CSP supplied) combined with vulnerable jQuery.
  • Privacy policy references third-party sharing without scoping to this extension's data handling.
  • Extension references external JS hosts (getbootstrap.com, popper.js.org) not covered by CSP.

Evidence

  • CVE findings: jquery@3.4.1 with CVE-2020-11022 and CVE-2020-11023 (medium severity, fixed in 3.5.0) crx Two medium XSS CVEs in bundled jquery@3.4.1; no CSP present to mitigate DOM-based XSS risk.
  • Privacy policy: fetched, scope_extension=false, data_collection=true, third_party_sharing=true store Policy admits data collection and third-party sharing but does not scope to this extension — D clause applies (+10.0).
  • No content_security_policy declared manifest csp_present=false; MV3 provides default but null CSP with external hosts is a concern.
  • External JS hosts: getbootstrap.com, github.com, popper.js.org, www.eclipse.org crx 4 distinct registrable domains referenced; all appear to be CDN/framework hosts, not threat-intel hits.
  • Developer domain kuario.com resolves, looks_throwaway=false, no bad/affiliate/monetization hits api Clean threat intel; domain appears legitimate business.
  • Maintenance: months_since_update=11 (6-12mo band) store Extension last updated July 31 2025; 6-12 month staleness window adds +3.5.
  • No rating, no install count available store Missing popularity data; not penalized further but reduces reputation confidence.
  • operator_cluster sibling_count=0, no wayback ownership change, no review red flags api No cluster risk, no ownership transfer detected, no negative review signals.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • printerProvider medium Allows extension to intercept print jobs; consistent with stated print function.
  • activeTab low Temporary access to active tab only; low risk.
  • windows low Can enumerate/manage browser windows; moderate but common for print UIs.
  • tabs medium Can read tab URLs and metadata across open tabs.
  • storage low Local extension storage only.
  • https://kuario.com/* low Scoped to developer's own domain; consistent with print service backend.
  • https://*.kuario.com/* low Scoped to developer's subdomains only.

Pillar Scores

Permissions2.30
Reputation5.00
Network2.00
Webstore0.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure2.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA ac259b76030b…
Force block — not fired
Score recovered no
Elapsed 27.2s