Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Free Spell Checker for Google Chrome™

ljgdcokhgjdpghmhdkbolccfcfdbklpo
Risk Score
7.06
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 30,000
Rating 4.0
Last updated 2023-10-27 (32 months ago)
Manifest version MV3
CSP present ❌ no
Developer mica.muller2022@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (arbitrary code execution) combined with no CSP; ×1.5 amplifier applied.
  • Brand impersonation: title uses 'Google Chrome™' trademark; dev is unverified gmail user with no business identity.
  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • Extension not updated in 32 months; stale libs with 3 jQuery medium CVEs and bad-host hit on js_external_hosts.
  • 12 external JS hosts including web.archive.org flagged as known-bad-host (URLHaus malware download).

Evidence

  • brand_impersonation store Title contains 'Google Chrome™'; brand_mention.is_impersonation=true; confirmed_owner=false; dev is gmail user.
  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, arbitrary code exec); not fixed until 1.12.1.
  • known_bad_host crx web.archive.org in js_external_hosts matched URLHaus malware_download host 154.216.19.139.
  • generic_privacy_policy store Policy URL is myaccount.google.com/privacypolicy; scope_extension=false; admits data_collection+third_party_sharing.
  • stale_extension_32mo store Last updated Oct 2023; 32 months stale; CVEs present; verified_publisher discount capped at -1.0 per 0c/v3.5E.
  • no_csp_with_cves manifest csp_present=false; jquery@1.9.1 has 3 XSS CVEs; ×1.5 amplifier on CVE pillar applied; code_quality boosted.
  • function_constructor_in_underscore crx new Function() call in underscore-min.js; paired with critical CVE-2021-23358 in same library.
  • free_webmail_no_dev_name store developer_name empty; email mica.muller2022@gmail.com; no business website; free-webmail floor applied.

CVE Exposures (6)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS
web.archive.org web.archive.org high [urlhaus/malware_download] URLHaus malware_download: 154.216.19.139,elf

Permissions Breakdown

  • storage low Stores extension settings locally; limited risk.
  • contextMenus low Adds right-click menu items; low capability.
  • host: https://languagetool.org/* medium Narrows outbound to single spell-check API domain; moderate since text may be sent.

Pillar Scores

Permissions0.60
Reputation8.50
Network4.50
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality5.00
CVE Exposure10.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:52
Listing SHA ba0f36788e87…
Force block — not fired
Score recovered no
Elapsed 32.3s