Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AI Grammar and Spell Checker by Ginger

kdfieneakcjfaiglcfcgkidlkmlijjnh
Risk Score
6.21
Risk Level: High
Recommendation: 🚫 BLOCK
Category AI
Installs 500,000
Rating 3.8
Last updated 2025-10-08 (8 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@gingersoftware.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • angular@1.8.3 carries 1 high + 5 medium CVEs (XSS, ReDoS) with no fixed version available; AngularJS is EOL.
  • Privacy policy fetched but scope_extension=false and admits third-party data sharing — worst-case Privacy pillar (10.0).
  • cookies + <all_urls> host access on 500K-user AI extension; every page the user visits is in scope.
  • CSP allows unsafe-eval on extension pages and sandbox; dynamic script creation found in code.
  • Uninstall URL redirects to gingersoftware.com; monetization signals (GTM, GA) in CSP and external hosts.

Evidence

  • angular@1.8.3 EOL with 9 CVEs (1 high, 5 medium, 3 low); no fixed_in version crx CVE-2024-21490 (high), CVE-2022-25869 (XSS moderate), plus 7 others — all unfixed.
  • CSP unsafe-eval on extension_page and sandbox crx script-src includes 'unsafe-eval' in both extension_page and sandbox CSP directives.
  • Privacy policy admits data collection + third-party sharing but not scoped to extension store scope_extension=false, data_collection=true, third_party_sharing=true per classification.
  • cookies permission paired with host_permissions https://*/ and http://*/ manifest Broad cookie access across all sites; AI extension processes page text on all URLs.
  • script_src_dynamic and function_constructor found in JS crx Dynamic script element creation in runtime JS; new Function() in writer.vendor.js.
  • dom_sink_innerhtml_userctrl in multiple content script files crx innerHTML sinks in content.min.js, definitionPopup/main.js, popup.min.js, writer.min.js.
  • uninstall_url_hijack to gingersoftware.com crx chrome.runtime.setUninstallURL points to https://www.gingersoftware.com/extension/uninstall?
  • verified_publisher + is_featured_by_google; no sibling clusters; domain resolves store Positive signals cap reputation discount; 0c applies due to monetization_hits nonempty.

CVE Exposures (9)

CVELibrarySeverity Fixed inSummary
CVE-2023-26117 angular@1.8.3 moderate angular vulnerable to regular expression denial of service via the $resource ser
CVE-2023-26116 angular@1.8.3 moderate angular vulnerable to regular expression denial of service via the angular.copy(
CVE-2024-21490 angular@1.8.3 high angular vulnerable to super-linear runtime due to backtracking
CVE-2025-0716 angular@1.8.3 low AngularJS improperly sanitizes SVG elements
CVE-2022-25844 angular@1.8.3 moderate angular vulnerable to regular expression denial of service (ReDoS)
CVE-2024-8372 angular@1.8.3 low AngularJS allows attackers to bypass common image source restrictions
CVE-2024-8373 angular@1.8.3 low AngularJS allows attackers to bypass common image source restrictions
CVE-2022-25869 angular@1.8.3 moderate Angular (deprecated package) Cross-site Scripting
CVE-2023-26118 angular@1.8.3 moderate angular vulnerable to regular expression denial of service via the <input type="

Permissions Breakdown

  • tabs medium Allows reading tab URLs and metadata across all open tabs.
  • background medium Persistent background execution; increases attack surface lifetime.
  • cookies high Can read/write cookies; paired with broad host access is HIGH×1.2 risk.
  • storage low Local extension storage; low standalone risk.
  • https://*/ high Broad host access to all HTTPS sites; combined with cookies is critical surface.
  • http://*/ high Broad host access to all HTTP sites; extends reach to insecure origins.
  • content_scripts <all_urls> high Content script injected into every page; full DOM read/write on all sites.

Pillar Scores

Permissions7.20
Reputation3.00
Network5.50
Webstore5.50
Maintenance1.50
Privacy10.00
Code Quality6.50
CVE Exposure8.25

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA e1c2ccea37c8…
Force block — not fired
Score recovered no
Elapsed 51.9s