Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Email Hunter

mbindhfolmpijhodmgkloeeppmkhpmhc
Risk Score
6.02
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 200,000
Rating 4.9
Last updated 2025-10-07 (8 months ago)
Manifest version MV3
CSP present ❌ no
Developer contacts.to.send@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail developer with no business domain; privacy policy is generic Google account policy, not scoped to this extension.
  • webRequest + scripting + <all_urls> gives full read/write capability on every page visited.
  • Multiple medium CVEs in bundled jQuery 1.9.1 and 3.3.1 with no CSP — XSS amplifier active.
  • No content security policy (MV3): CVE-bearing jQuery + no CSP elevates exploitability.
  • 200K installs with high-capability permissions from an unverified free-webmail developer raises supply-chain risk.

Evidence

  • free_webmail_developer store Developer is contacts.to.send@gmail.com — no verified business domain; reputation floor 7.5 applies.
  • generic_privacy_policy store Privacy policy links to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
  • cve_jquery_1.9.1 crx jquery@1.9.1 has 3 medium CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); no CSP present.
  • cve_jquery_3.3.1 crx jquery@3.3.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); unfixed versions bundled.
  • no_csp_with_cves manifest content_security_policy is null; CVE-bearing jQuery + no CSP triggers v2e +2.0 Code Quality amplifier.
  • broad_host_permissions manifest <all_urls> host permission paired with webRequest and scripting = full-page surveillance + injection.
  • function_constructor_code crx new Function() constructor found in lib/lib.js; +2.5 Code Quality per function_constructor signal.
  • is_featured_by_google store Featured badge present; applied -2.0 Reputation discount but free-webmail floor overrides to 7.5.

CVE Exposures (6)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • notifications medium Can push notifications to user; medium nuisance/phishing risk.
  • storage low Local data persistence only.
  • alarms low Scheduled background tasks; low standalone risk.
  • webRequest high Observe all network requests across all URLs; broad surveillance surface.
  • webNavigation medium Tracks user navigation events across all sites.
  • scripting high Programmatic script injection into any page via <all_urls>.
  • <all_urls> (host_permissions) high Combined with scripting/webRequest gives full read/write on every site.

Pillar Scores

Permissions7.50
Reputation7.50
Network4.50
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality4.50
CVE Exposure5.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA 972c5de6c2a9…
Force block — not fired
Score recovered no
Elapsed 30.3s