Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Search All

kpdkbemdpepjjppbfgeapjienologapa
Risk Score
6.14
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 30,000
Rating 4.4
Last updated
Manifest version MV3
CSP present ✅ yes
Developer care@awesomescreenshot.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@1.7.1 bundles 5 moderate CVEs (XSS); version far behind fixed releases up to 3.5.0.
  • Content scripts on <all_urls> with DOM innerHTML sink in process.js creates XSS attack surface on every page.
  • Privacy policy fetched but scope_extension=false AND admits data_collection+third_party_sharing — scores 10.0 (v3.5 rule D).
  • code_quality 7.5 (function_constructor + script_src_dynamic + innerHTML sink + CVE combo) triggers block threshold.
  • History + tabs + bookmarks + <all_urls> gives broad browsing profile capture capability; maintenance date unknown.

Evidence

  • cve_jquery_1.7.1 crx 5 moderate CVEs in bundled jquery@1.7.1; fixed_in ranges 1.9.0–3.5.0; library not updated.
  • code_function_constructor crx new Function() constructor in js/jquery.js — dynamic code execution path.
  • code_script_src_dynamic crx Dynamic <script> element creation in js/jquery.js — remote script loading risk.
  • code_innerhtml_sink crx innerHTML assigned from variable in js/process.js; combined with CVEs raises XSS risk.
  • privacy_policy_scope_mismatch api Policy admits data_collection+third_party_sharing but scope_extension=false — generic policy, triggers +10.0.
  • host_permissions_all_urls manifest <all_urls> content scripts on every page combined with history/tabs/bookmarks access.
  • js_external_hosts_12 crx 12 external JS hosts including go.redirectingat.com and www.searcho.com — potential affiliate/redirect surface.
  • featured_by_google store is_featured_by_google=true; reduces reputation risk but does not override code/privacy findings.

CVE Exposures (5)

CVELibrarySeverity Fixed inSummary
CVE-2012-6708 jquery@1.7.1 moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2019-11358 jquery@1.7.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.7.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-7656 jquery@1.7.1 moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2015-9251 jquery@1.7.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • contextMenus low Adds right-click menu items; low standalone risk.
  • unlimitedStorage low Allows extended local storage; no data exfil by itself.
  • storage low Standard local data persistence.
  • tabs medium Can read tab URLs/titles across all open tabs.
  • bookmarks medium Full read/write access to user bookmarks.
  • history medium Full browsing history access — sensitive PII surface.
  • offscreen low Off-screen document rendering; low direct risk.
  • activeTab low Scoped to current tab on user action.
  • favicon low Read favicon URLs; minimal risk.
  • <all_urls> (host_permissions) high Content scripts run on every page; broad DOM/data access across all sites.
  • *://*.images.google.com/ (host_permissions) low Specific subdomain; narrower than <all_urls> but overlaps with it.

Pillar Scores

Permissions7.50
Reputation3.50
Network3.50
Webstore4.50
Maintenance5.00
Privacy10.00
Code Quality7.50
CVE Exposure5.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:50
Listing SHA 6f8ac3d31445…
Force block — not fired
Score recovered no
Elapsed 35.1s