Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Webpage Spell-Check

mgdhaoimpabdhmacaclbbjddhngchjik
Risk Score
6.59
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Productivity
Installs 20,000
Rating 2.7
Last updated 2023-11-18 (31 months ago)
Manifest version MV3
CSP present ❌ no
Developer gakbar@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@1.12.4 bundles 4 medium CVEs (XSS); no CSP to mitigate; version far below fixed_in 3.5.0
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension
  • Extension not updated in 31 months (zombie); stale CVE-laden jQuery poses persistent XSS risk
  • Broad content_script on all HTTP/HTTPS pages with innerHTML sink — DOM-XSS vector on every site
  • Gmail dev, no developer name, low rating 2.7; verified publisher but no recognized org identity

Evidence

  • jquery_cve_cluster crx 4 medium CVEs in jquery@1.12.4 (CVE-2015-9251, CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
  • no_csp manifest content_security_policy is null; no CSP mitigation for DOM-XSS or dynamic script loading.
  • privacy_policy_inadequate store Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — generic admitting policy.
  • stale_extension store Last updated November 2023; 31 months since update. Triggers 24-36mo maintenance band (+8.5).
  • broad_host_access_content_script manifest content_scripts_matches http://*/* and https://*/* — runs on every page visited.
  • dom_xss_sink crx innerHTML assigned from variable in spellcheck-extension.js with no CSP and CVEs present — elevated DOM-XSS risk.
  • free_webmail_dev_no_name store developer_email=gakbar@gmail.com, developer_name empty; verified_publisher=true caps floor at 2.0.
  • low_rating store Rating 2.7; count unknown but signal is negative user sentiment.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.12.4 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@1.12.4 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.12.4 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Stores extension settings locally; limited blast radius.
  • http://*/* high Broad host access to all HTTP pages via content_scripts; enables DOM manipulation on every site.
  • https://*/* high Broad host access to all HTTPS pages; same risk surface as http://*/*.

Pillar Scores

Permissions5.50
Reputation7.00
Network3.00
Webstore3.50
Maintenance8.50
Privacy10.00
Code Quality5.50
CVE Exposure6.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:55
Listing SHA 61b88b3c63f6…
Force block — not fired
Score recovered no
Elapsed 28.8s