Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Grammar Checker

mpeepmfabickbdbckcejbflkpfamgcon
Risk Score
4.71
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 40,000
Rating 4.3
Last updated 2026-03-13 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@linangdata.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; unfixed.
  • Known-bad-host hit: web.archive.org resolves to URLHaus malware_download IP in JS host list.
  • Privacy policy fetch failed (HTTP error); policy adequacy cannot be verified — scored as no policy.
  • No CSP on MV3 extension with function_constructor finding in underscore; code execution risk elevated.
  • No developer name listed; developer identity limited to email domain linangdata.com.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (Arbitrary Code Execution); fixed_in 1.12.1, not updated.
  • known_bad_host crx web.archive.org appears in js_external_hosts; URLHaus flags IP 154.216.19.139 as malware_download.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (fetch_error:HTTPError); treated as no policy.
  • function_constructor_no_csp crx new Function() in underscore-min.js; csp_present==false amplifies code execution risk.
  • no_developer_name store developer_name is empty string; only identity signal is info@linangdata.com.
  • external_hosts_broad crx 12 distinct external JS hosts including languagetool.org, github.com, stackoverflow.com, web.archive.org.
  • verified_publisher store verified_publisher==true; applies reputation discount but capped due to bad-host hit (invariant 0c/E).
  • high_cve_underscore crx CVE-2026-27601 high-severity DoS in underscore@1.8.3; fixed_in 1.13.8, currently unfixed.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS
web.archive.org web.archive.org high [urlhaus/malware_download] URLHaus malware_download: 154.216.19.139,elf

Permissions Breakdown

  • contextMenus low Adds right-click menu items; no data access on its own.

Pillar Scores

Permissions0.30
Reputation5.00
Network3.50
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure9.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:57
Listing SHA 39d8ae8d23e7…
Force block — not fired
Score recovered no
Elapsed 25.2s