Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Find The Recipe

naaffooocnnodpcmppdjhpjiogkljkch
Risk Score
5.34
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 9,000
Rating
Last updated 2024-11-04 (22 months ago)
Manifest version MV3
CSP present ❌ no
Developer nicks@worthathousandwords.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Search provider override (is_default=true) silently redirects ALL omnibar queries to findtherecipe.com.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
  • Bundled jquery@3.3.1 carries 3 moderate XSS CVEs (fixed in 3.5.0), extension not updated in 22 months.
  • No developer name listed; developer identity accountability is low.
  • Extension stale 22 months with known-vulnerable library and no CSP on popup, raising XSS exploitation risk.

Evidence

  • search_provider_override manifest chrome_settings_overrides.search_provider.is_default=true routes all searches to findtherecipe.com/ext/search.
  • privacy_policy_inadequate crx Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — admits sharing without extension scope.
  • cve_jquery_3.3.1 crx 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) in bundled jquery@3.3.1; fixed in 3.5.0.
  • stale_extension store Last updated November 2024, 22 months ago; vulnerable library not patched.
  • no_developer_name store developer_name is empty; no 'Offered by' identity shown in store listing.
  • no_csp manifest content_security_policy is null; MV3 default applies but popup uses jquery with XSS CVEs and no explicit CSP.
  • no_rating store Rating 0 with 0 ratings on 9,000 installs; no community trust signal.
  • v2_calibration_search_override_permissions manifest Search-provider override scored +2.0 on Permissions per rubric rule (a) for chrome_settings_overrides.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • search medium Allows overriding the default search engine; paired with chrome_settings_overrides it redirects all searches.
  • chrome_settings_overrides.search_provider (is_default=true) high Forces itself as default search engine, capturing every omnibar query and routing through findtherecipe.com.
  • host_permissions: https://findtherecipe.com/* low Narrow host permission scoped to developer's own domain only.

Pillar Scores

Permissions5.00
Reputation6.00
Network2.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 06:15
Listing SHA aab31c0e331d…
Force block — not fired
Score recovered no
Elapsed