Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Track Package​

onjnkdhpnecgfhnplplfidpjbalmppoo
Risk Score
5.78
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 81
Rating 1.0
Last updated 2025-02-19 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@bestfreemaps.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits 3rd-party sharing but not scoped to this extension — effectively a generic data-collection policy.
  • Uninstall and install URL hijacks detected — classic traffic-monetization shell pattern.
  • Content script on <all_urls> paired with 9 external JS hosts including s1search.co and aakkgo.com.
  • jquery@3.3.1 carries 3 medium XSS CVEs (unfixed); no CSP amplifies DOM-XSS risk.
  • 19 months stale, 1-star rating, and bestfreemaps.com domain irrelevant to package tracking.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both onInstalled and uninstall URL callbacks set to 3rd-party destinations — monetization shell indicator.
  • privacy_policy scope_extension=false, data_collection=true, third_party_sharing=true api Policy admits data collection and 3rd-party sharing without scoping to this extension → +10.0 privacy (v3.5 rule D).
  • content_scripts <all_urls> manifest Broad content script injection into every site visited by user, combined with tabs permission.
  • js_external_hosts suspicious domains crx Hosts include aakkgo.com, mapsm.com, www-bestfreemaps-com.s1search.co — unrelated to package tracking.
  • jquery@3.3.1 CVEs crx 3 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0, bundled 3.3.1.
  • no CSP + dom_sink_innerhtml_userctrl + CVEs crx innerHTML from variable in index1.js with no CSP and active jQuery XSS CVEs → elevated DOM-XSS code quality score.
  • months_since_update=19, rating=1 store 19 months stale (6-12mo band but >18mo triggers 0c cap); 1-star rating signals user dissatisfaction.
  • developer domain mismatch store Developer is bestfreemaps.com; privacy policy hosted on xpackage.me; extension tracks packages — brand coherence absent.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • tabs medium Can read tab URLs and titles across all tabs.
  • activeTab low Grants access only to user-activated tab; low surface area alone.
  • storage low Local key-value storage; no direct data-exfil capability.
  • content_scripts:<all_urls> high Content script injected into every page; broad DOM access across all origins.

Pillar Scores

Permissions3.50
Reputation6.50
Network4.50
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-02 15:49
Listing SHA a745e7798340…
Force block — not fired
Score recovered no
Elapsed