Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Pay with BitPay

jkjgekcefbkpogohigkgooodolhdgcda
Risk Score
4.61
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 8,000
Rating 4.7
Last updated 2025-07-29 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer integrations@bitpay.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Broad content_scripts on http://*/*+https://*/*oliciting all pages; scripting permission amplifies reach.
  • Privacy policy fetched but does NOT scope to this extension; admits data collection and third-party sharing (D rule → +10.0).
  • Uninstall URL hijack flag set (uninstall_url_hijack=true) — could route users to third-party post-removal.
  • dom_sink_innerhtml_userctrl in bundled React bundle — DOM-XSS sink executed across all sites.
  • developer_name empty; no verified publisher badge; no brand confirmation despite bitpay.com domain.

Evidence

  • broad_host_permissions manifest host_permissions and content_scripts_matches both cover http://* and https://* — runs on every site.
  • uninstall_url_hijack crx uninstall_url_hijack=true; target unknown — potential post-uninstall redirect to third party.
  • privacy_policy_generic store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5 D rule +10.0.
  • dom_xss_sink crx innerHTML assigned from variable in js/options.bundle.js — DOM-XSS risk on options page.
  • google_analytics_telemetry crx connect-src includes google-analytics.com; monetization_hits lists it as telemetry tier only.
  • no_developer_name store developer_name field empty; email integrations@bitpay.com suggests legitimate org but unverified.
  • js_external_hosts crx 8 external hosts in CSP/JS: bitpay.com, fonts.googleapis.com, gravatar.com, github.com, reactjs.org, etc.
  • cve_findings_empty crx No CVEs detected in bundled libraries; cve_findings_raw is empty.

Permissions Breakdown

  • activeTab low Scoped to current tab on user action only.
  • storage low Local preference/settings storage, low impact.
  • scripting high Can inject JS into pages; combined with broad host_permissions this is high risk.
  • http://*/* high Broad host access across all HTTP sites for content script injection.
  • https://*/* high Broad host access across all HTTPS sites for content script injection.

Pillar Scores

Permissions5.00
Reputation5.00
Network2.50
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:46
Listing SHA c4e4ccfa187f…
Force block — not fired
Score recovered no
Elapsed 23.3s