Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Boomerang for Gmail

mdanidgdpmkimeiiojknlnekblgmpdll
Risk Score
7.45
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 800,000
Rating 4.2
Last updated 2026-07-09 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@baydin.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • MANAGEMENT PERMISSION: extension can enumerate and disable other installed extensions (incl. security and privacy tools).
  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing==true triggers +10.0 Privacy score.
  • 6 medium-severity CVEs in bundled jquery@1.5.2 (far below fixed_in 3.5.0); no CSP amplifies XSS risk on Gmail DOM.
  • Code findings: eval_user_input + function_constructor + script_src_dynamic in bookmarklet JS with no CSP.
  • 'management' permission allows extension to enumerate/disable/uninstall other installed extensions.

Evidence

  • management_permission manifest 'management' is HIGH-risk; allows disabling/uninstalling other extensions without user prompt.
  • no_csp crx content_security_policy is null; MV3 default applies but no explicit lock-down; amplifies CVE/eval risk.
  • jquery_cves crx jquery@1.5.2 carries 6 moderate CVEs; fixed versions range from 1.6.3 to 3.5.0; library is unpatched.
  • eval_and_dynamic_script crx eval_user_input + function_constructor + script_src_dynamic all present in b4g_bookmarklet_1.8.7.js.
  • privacy_policy_scope_mismatch store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic non-scoped policy.
  • external_hosts_breadth crx 12 external JS hosts including s3.amazonaws.com, jsfiddle.net — wider than expected for an email scheduler.
  • featured_by_google store Extension carries Google Featured badge; partial reputation credit applied.
  • baydin_domain_resolves api developer_domain baydin.com resolves; looks_throwaway=false; no bad_host or affiliate hits.

Permissions Breakdown

  • management high Can enumerate, disable, or uninstall other extensions — significant privilege.
  • activeTab low Access only to the currently active tab on user gesture; limited scope.
  • content_scripts: https://mail.google.com/* medium Injects JS into Gmail; appropriate for function but reads all email page content.

Pillar Scores

Permissions7.50
Reputation3.50
Network4.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality8.00
CVE Exposure5.25

Scoring History

&#x22;fsssiedxefdsaxax><!--></ScRiPt>asddsssiedx 4.71 Medium review 2026-08-24
fsssiedxe<sssiedx 5.02 Medium review 2026-08-24
v3.69946/"();}]9598 5.09 Medium review 2026-08-05
v3.6"onmouseover=jFtY(96952)" 4.44 Medium review 2026-08-05
dfb__${98991*97996}__::.x 4.55 Medium review 2026-08-05
v3.6'"()&%<zzz><ScRiPt >jFtY(9389)</ScRiPt> 4.55 Medium review 2026-08-05
v3.6&n952725=v997451 4.64 Medium review 2026-08-05
v3.6&n912981=v962801 5.16 Medium review 2026-07-29
sssieddrubricxsx 5.09 Medium review 2026-07-28
v3.6 7.45 High block 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-15 13:43
Listing SHA 4983bf2f9f4c…
Force block — not fired
Score recovered no
Elapsed 53.7s