Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Shopify Theme Detector

npjkomjipdbengebpldgodddlinfjhhm
Risk Score
6.11
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category DeveloperTools
Installs 20,000
Rating 3.4
Last updated 2024-04-30 (26 months ago)
Manifest version MV3
CSP present ✅ yes
Developer info@scanwp.net
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: extension mentions 'Shopify' but developer is unaffiliated (scanwp.net), no verified publisher badge.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and third-party sharing.
  • Three medium-severity CVEs in bundled jquery@1.11.3 (XSS); library far behind fixed versions.
  • Content scripts run on <all_urls> with 26 months without update — stale, high-reach attack surface.
  • No developer name listed; low rating (3.4) increases credibility concern.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true for 'shopify'; confirmed_owner=false; developer is scanwp.net.
  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • cve_jquery_medium crx 3 medium CVEs in jquery@1.11.3 (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed_in up to 3.5.0.
  • content_scripts_all_urls manifest content_scripts_matches=["<all_urls>"] — extension runs on every visited page.
  • stale_extension store Last updated April 2024; months_since_update=26, triggering +8.5 maintenance score.
  • no_developer_name store developer_name is empty string; only info@scanwp.net available.
  • script_src_dynamic crx jquery.min.js creates dynamic <script> elements — scores +3.0 code quality.
  • triple_stale_fingerprint store >24mo + CVEs present + MV3 (MV2 rule N/A) — v2 calibration +2.0 webstore applied for stale+CVE combo.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.11.3 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.11.3 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.11.3 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • scripting medium Can inject scripts into pages; paired with <all_urls> content_scripts raises reach.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • content_scripts:<all_urls> high Scripts execute on every site the user visits, broad data access surface.

Pillar Scores

Permissions4.50
Reputation7.00
Network0.00
Webstore5.50
Maintenance8.50
Privacy10.00
Code Quality3.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:00
Listing SHA ac69b7c9c212…
Force block — not fired
Score recovered no
Elapsed 27.3s