Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Ref Schedule Sync

pgdajjngmjfhnoghgoddckkikijklaib
Risk Score
5.88
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 4
Rating
Last updated 2021-12-05 (56 months ago)
Manifest version MV3
CSP present ✅ yes
Developer matthew.rosenfeld22@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned: 56 months since last update, no maintenance for nearly 5 years.
  • Privacy policy is Google's own policy, not scoped to this extension — admits data collection and 3rd-party sharing.
  • Bundled jquery@3.3.1 has 3 moderate CVEs (XSS); unfixed since extension is stale.
  • Developer uses free Gmail account with no verified business identity; brand_mention flags Google impersonation.
  • Generic policy admits data_collection and third_party_sharing without extension-specific scope.

Evidence

  • stale_extension store Last updated December 2021; 56 months elapsed — well past 36-month zombie threshold.
  • privacy_policy_generic store Privacy URL points to Google's global policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • cve_moderate_jquery crx jquery@3.3.1 has 3 moderate CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); fixed_in 3.5.0.
  • free_webmail_developer store Developer email matthew.rosenfeld22@gmail.com; no verified publisher, no business domain.
  • brand_impersonation store brand_mention.is_impersonation=true (Google mentioned); developer domain is gmail.com, confirmed_owner=false.
  • very_low_installs store Only 4 installs; limited blast radius but tail-attack-surface concern absent (no high-tier perms).
  • content_scripts_narrow manifest Content scripts scoped to two specific referee scheduling domains; matches stated function.
  • js_external_hosts crx External JS hosts limited to accounts.google.com and www.googleapis.com; consistent with Google Calendar OAuth.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.3.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.3.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Stores local extension data; low risk.
  • tabs medium Can read tab URLs/titles; medium risk without broad host access.
  • identity medium OAuth token access; used here for Google Calendar API.
  • content_scripts: horizonwebref.com + arbitersports.com low Narrowly scoped to two referee scheduling sites; matches stated function.

Pillar Scores

Permissions2.00
Reputation7.50
Network1.00
Webstore3.50
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:18
Listing SHA 84438af2e338…
Force block — not fired
Score recovered no
Elapsed