Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Wischat

mehipcdhalmoecjhhfcgmiodeokllnno
Risk Score
3.39
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 70
Rating
Last updated 2026-08-03
Manifest version MV3
CSP present ❌ no
Developer comercial@nouxsoft.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • jQuery 3.4.1 bundled with 2 medium CVEs (XSS); no CSP amplifies risk per v2 CVE amplifier.
  • Privacy policy not scoped to this extension and lacks retention/third-party details; +9.0 privacy score.
  • bit.ly host permission flagged as affiliate/cloaking vector by threat_intel.
  • dom_sink_innerhtml_userctrl in strophe.umd.min.js with no CSP raises DOM-XSS surface.
  • disisot.com host permission unexplained by stated function.

Evidence

  • jquery_cve_no_csp crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (medium XSS); no CSP present — v2 amplifier ×1.5 applies.
  • privacy_policy_not_scoped api Privacy policy fetched but scope_extension=false, data_collection=false → +9.0 privacy pillar.
  • affiliate_hit_bitly crx bit.ly in host_permissions; threat_intel flags as affiliate/cloaking redirector.
  • dom_xss_sink_no_csp crx innerHTML sink in strophe.umd.min.js; csp_present=false triggers +2.0 code quality rule FIX B.
  • unexplained_host_disisot manifest disisot.com host permission not mentioned in description or store page.
  • verified_publisher store verified_publisher=true; nouxsoft.com resolves, no throwaway flag — provides partial reputation credit.
  • no_developer_name store developer_name is empty string; no 'Offered by' display name visible.
  • low_installs store Only 70 installs; blast radius low but tail_attack_surface not triggered per anomaly check.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Local data persistence; low sensitivity.
  • scripting medium Allows programmatic script injection into pages.
  • *://*.whatsapp.com/* medium Access to WhatsApp web; matches stated function (chat integration).
  • *://*.wis.chat/* low Dev-controlled domain; expected for product backend.
  • *://*.disisot.com/* medium Unknown third-party domain; unexplained host access.
  • *://*.wa.link/* low WhatsApp short-link domain; ancillary to chat function.
  • *://*.wa.me/* low WhatsApp click-to-chat domain; ancillary to chat function.
  • *://bit.ly/* medium Generic URL shortener; affiliate/cloaking risk flagged by threat_intel.
  • *://localhost/* low Local dev endpoint; low real-world impact.
  • *://127.0.0.1/* low Loopback only; dev/debug pattern.

Pillar Scores

Permissions2.30
Reputation4.50
Network3.50
Webstore2.00
Maintenance0.00
Privacy9.00
Code Quality2.50
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:54
Listing SHA 46f01a3291e9…
Force block — not fired
Score recovered no
Elapsed