Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Calendar Selector for Google Calendar

nmliklikilkjommabacojbijjimlgjck
Risk Score
4.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 40,000
Rating 4.5
Last updated 2025-08-16 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@bluenexa.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • jQuery 2.0.0 bundled with 4 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251); no CSP to mitigate.
  • Brand-mention impersonation flag: extension name/listing references 'Google' but developer is not Google and is not verified.
  • Privacy policy linked is Google's global account policy, not a developer-authored policy for this extension.
  • No CSP declared (MV3 default applies but no explicit hardening); innerHTML DOM-XSS sink in bundled jQuery.

Evidence

  • privacy_policy_generic_google store Privacy policy URL points to myaccount.google.com — Google's own policy, not the developer's. scope_extension=false, data_collection=true, third_party_sharing=true.
  • cve_jquery_moderate_x4 crx jquery@2.0.0 bundles CVE-2019-11358, CVE-2020-11022, CVE-2020-11023, CVE-2015-9251 (all moderate XSS). fixed_in 3.5.0.
  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=['google']; developer is Bluenexa LLC, not verified publisher, not Google.
  • dom_sink_innerhtml crx lib/jquery/jquery.js: innerHTML assignment from variable — DOM-XSS sink; no CSP present to mitigate.
  • no_csp_mv3 manifest content_security_policy is null; MV3 default applies but no explicit CSP hardening declared.
  • host_permissions_narrow manifest host_permissions limited to https://calendar.google.com/* — narrow and matches stated function.
  • featured_by_google store is_featured_by_google=true; provides partial reputation credit but does not resolve impersonation or privacy policy issues.
  • operator_cluster_clean api sibling_count=0; no related suspicious extensions under same fingerprint. Domain bluenexa.com resolves, not throwaway.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@2.0.0 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.0.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.0.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.0.0 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Saves/restores calendar group settings locally; expected for this function.
  • https://calendar.google.com/* medium Content script scoped to single Google Calendar domain; narrow but sensitive.

Pillar Scores

Permissions1.30
Reputation5.00
Network2.00
Webstore3.50
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:59
Listing SHA 358a0c739735…
Force block — not fired
Score recovered no
Elapsed 27.0s