Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MailTracker: Email tracker for Gmail

pgbdljpkijehgoacbjpolaomhkoffhnl
Risk Score
4.08
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 100,000
Rating 4.7
Last updated 2026-03-11 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer hello@getmailtracker.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • jquery@3.1.1 bundles 3 moderate CVEs (XSS); no CSP amplifies DOM-XSS risk via innerHTML sinks.
  • Privacy policy admits data collection and third-party sharing but lacks data retention disclosure.
  • new Function() constructor in content-script context enables dynamic code execution risk.
  • Uninstall URL redirects to developer-controlled endpoint; install_url_hijack also flagged.
  • No developer name listed; no verified publisher badge; email-only identity with self-hosted domain.

Evidence

  • cve_findings_raw: 3x moderate jquery@3.1.1 CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023) crx jquery@3.1.1 below fixed_in 3.5.0; XSS vulnerabilities in DOM-manipulation lib with no CSP present.
  • no content_security_policy + CVEs in jquery (DOM-manipulation lib) manifest csp_present=false with jquery CVEs triggers CVE amplifier ×1.5 on CVE pillar.
  • code_findings: function_constructor + 2x dom_sink_innerhtml_userctrl crx new Function() in pageWorld/index.js; innerHTML sinks in userEvents and webcomponents-bundle without CSP.
  • privacy policy: data_collection=true, third_party_sharing=true, retention=false store Policy scoped to extension but admits 3rd-party sharing with no retention clause.
  • uninstall_url_hijack=true; install_url_hijack=true crx chrome.runtime.setUninstallURL points to app.getmailtracker.com/uninstall; install opens 3rd-party URL.
  • developer_name empty; not verified publisher; not featured store No 'Offered by' name in listing; email hello@getmailtracker.com on own domain.
  • js_external_hosts includes mailtracker.ngrok.io, polymer.github.io, reactjs.org crx ngrok dev-tunnel host in production build suggests incomplete cleanup; 4 registrable domains.
  • is_featured_by_google=true; rating 4.7; no bad_host_hits; no monetization_hits store Featured badge and clean threat-intel partially offset reputation concerns.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2020-11023 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@3.1.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • declarativeNetRequest medium Can block/modify network requests; scoped to mail.google.com host is functional fit.
  • storage low Local data persistence; standard for extension state.
  • scripting medium Allows script injection into pages; paired with mail.google.com host permission.
  • *://mail.google.com/ medium Access to Gmail DOM and email content; expected for email-tracker category.
  • *://mailtracker.hunter.io/ medium Access to developer's own tracking dashboard; narrow scope.

Pillar Scores

Permissions3.00
Reputation5.50
Network3.50
Webstore3.50
Maintenance0.00
Privacy2.00
Code Quality4.50
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:04
Listing SHA 162418cf52f5…
Force block — not fired
Score recovered no
Elapsed 35.2s