Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Url Shortener

oodfdmglhbbkkcngodjjagblikmoegpa
Risk Score
4.05
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 300,000
Rating 3.8
Last updated 2026-03-16 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@t.ly
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL fetch failed — privacy posture completely unknown for 300K users.
  • jquery@1.9.1 bundled in bootstrap.min.js carries 3 moderate XSS CVEs; no CSP to mitigate.
  • No CSP + innerHTML sink in sweetalert2 + vulnerable jQuery = elevated DOM-XSS risk.
  • Developer name absent; looks_throwaway flag on t.ly domain reduces accountability.
  • Install-URL and uninstall-URL both point to t.ly — install hijack pattern noted.

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (HTTPError); policy scored +10.0.
  • cve_moderate_x3_jquery_1.9.1 crx CVE-2015-9251, CVE-2019-11358, CVE-2020-11023 in jquery@1.9.1 via bootstrap.min.js; fixed_in 3.5.0.
  • no_csp_mv3 manifest content_security_policy is null; no CSP mitigations for XSS sinks.
  • dom_xss_sink_no_csp crx dom_sink_innerhtml_userctrl in sweetalert2@8.js; csp_present=false triggers +2.0 code quality.
  • install_url_hijack crx onInstalled opens https://t.ly/register?ref=extension-install — install URL hijack.
  • developer_name_missing_looks_throwaway store developer_name empty; threat_intel.looks_throwaway=true for t.ly domain.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; discounts applied to reputation.
  • 10_external_js_hosts crx 10 distinct external hosts contacted (api.t.ly, api.rebrandly.com, getbootstrap.com, etc.).

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • activeTab low Access only to current tab on user action; narrow scope for a URL shortener.
  • contextMenus low Adds right-click menu items; standard for shortening selected URLs.
  • storage low Local settings/preferences storage; limited exfil surface.

Pillar Scores

Permissions1.00
Reputation4.50
Network2.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:02
Listing SHA a4c8c65b6357…
Force block — not fired
Score recovered no
Elapsed 27.3s