Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VPN unlimited, free VPN with private browsing

nagcmbgoldfkmkiennnjpmfkfcpdgmbk
Risk Score
6.94
Risk Level: High
Recommendation: 🚫 BLOCK
Category VPN
Installs 3,000
Rating 2.4
Last updated 2022-10-16 (47 months ago)
Manifest version MV3
CSP present ❌ no
Developer steven.dujardin67@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • proxy + <all_urls> lets extension silently reroute all browser traffic through arbitrary servers — critical for unverified VPN.
  • Developer is free-webmail gmail user with no verified business; no accountability for traffic interception.
  • Privacy policy on Google Sites admits data collection and third-party sharing without scoping to this extension — effectively admits data sale.
  • Last updated 47 months ago (Oct 2022); abandoned extension with HIGH-capability permissions is prime acquisition/compromise target.
  • Bundled jquery@1.9.1 carries 3 medium XSS CVEs (unfixed); no CSP amplifies exploitability via jquery×no-CSP rule.

Evidence

  • proxy + broad host permissions manifest proxy declared alongside *://*/* and <all_urls>; can intercept and reroute all HTTPS/HTTP traffic.
  • free-webmail developer, no verified publisher store steven.dujardin67@gmail.com with no business domain; verified_publisher=false, is_featured=false.
  • privacy policy admits collection + third-party sharing, not scoped to extension api scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (D rule).
  • abandoned extension — 47 months since update store Last updated Oct 2022; >36 months triggers max maintenance score of 10.0.
  • jquery@1.9.1 bundled with 3 medium CVEs, no CSP crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11023; no content_security_policy; jquery<3.5+no-CSP amplifier applies.
  • uninstall URL hijack present crx chrome.runtime.setUninstallURL() called; target null in scan but hijack flag true — +3.0 webstore.
  • rating 2.4 — below 3.0 store Low rating increases reputation risk signal (+1.0), though rating_count not confirmed >= 50.
  • tail_attack_surface anomaly api install_perm_anomaly.tail_attack_surface=true; high-tier permissions on low-install extension.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Local key-value storage; minimal risk.
  • unlimitedStorage low Extends storage quota; low standalone risk.
  • proxy high Can reroute all browser traffic through attacker-chosen proxy; critical for VPN but high-risk.
  • *://*/* high Broad host access across all sites; paired with proxy amplifies traffic interception risk.
  • <all_urls> high Redundant with *://*/* — grants full URL access; combined ×1.2 multiplier applies.

Pillar Scores

Permissions8.00
Reputation7.50
Network4.50
Webstore6.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure3.75

Bookkeeping

Rubric v3.6
Scored at 2026-09-15 12:15
Listing SHA c9b00c0c6324…
Force block — not fired
Score recovered no
Elapsed