Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sprint Reader - Speed Reading Extension

kejhpkmainjkpiablnfdppneidnkhdif
Risk Score
4.49
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category ReaderMode
Installs 20,000
Rating 4.4
Last updated 2025-09-05 (9 months ago)
Manifest version MV3
CSP present ✅ yes
Developer anthonynosek@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • 4 medium-severity CVEs in bundled jquery@2.0.3 (unfixed; fixed_in 3.5.0); known-bad-host hit on web.archive.org reference.
  • Privacy policy is Google's generic account policy — not scoped to this extension, yet admits data collection and third-party sharing.
  • 5 innerHTML DOM-XSS sinks across production and lib files combined with CVE-laden jQuery raise XSS chained-exploit risk.
  • Content scripts injected on all http/https sites; gmail.com developer email means no verifiable business identity.
  • Geo-diverse external JS hosts (4 countries) including languid.cantbedone.org and excamera.com — unusual for a reader extension.

Evidence

  • jquery@2.0.3 — 4 moderate CVEs bundled, none patched crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023; fixed_in 3.5.0, current 2.0.3.
  • known-bad-host web.archive.org in js_external_hosts crx URLHaus malware_download hit on 154.216.19.139 associated with web.archive.org reference.
  • Privacy policy is Google account generic policy store scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar 10.0.
  • Developer email is free webmail (gmail.com), no business domain store anthonynosek@gmail.com; domain_age_ct not queried; no verified publisher badge.
  • 5 innerHTML DOM-XSS sinks in production and lib files crx dom_sink_innerhtml_userctrl in facts.js, engine.js, reader.js, colorpicker, qunit.
  • Content scripts on all http/https sites manifest content_scripts_matches: http://*/* and https://*/* — broad reach for a reader.
  • 12 external JS hosts across 4 countries crx Hosts include languid.cantbedone.org, excamera.com, websvn.kde.org — geo-diversity count 4.
  • is_featured_by_google=true partially offsets reputation risk store Featured badge applied; no verified publisher badge; free-webmail dev email remains.

CVE Exposures (5)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.0.3 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.0.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.0.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.0.3 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
web.archive.org web.archive.org high [urlhaus/malware_download] URLHaus malware_download: 154.216.19.139,elf

Permissions Breakdown

  • contextMenus low Adds right-click menu items; limited blast radius.
  • activeTab low Access limited to the current tab on user gesture.
  • clipboardRead medium Can read clipboard content; text pasted for speed-reading plausible but sensitive.
  • storage low Local preference storage; low risk.
  • system.display low Read display metrics; useful for layout, no data exfil path.
  • content_scripts http://*/* https://*/* medium Broad content-script injection on all sites; elevated reach for a reader extension.

Pillar Scores

Permissions3.30
Reputation6.50
Network1.50
Webstore2.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure6.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:48
Listing SHA 6b3d7aec7e60…
Force block — not fired
Score recovered no
Elapsed 38.8s