Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SpeedUp: Netflix, Prime videos

pldkddbkbcedophgedaeofceedjcaehl
Risk Score
6.06
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Entertainment
Installs 30,000
Rating 4.2
Last updated 2026-07-16 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer businessinsider11@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: names Netflix, Amazon, YouTube, Twitch, Reddit without ownership; gmail dev with no verified business.
  • Privacy policy is Google's generic policy — scope_extension=false, admits data_collection+third_party_sharing; effectively no extension-specific policy.
  • jquery@3.4.1 with two XSS CVEs (CVE-2020-11022, CVE-2020-11023) bundled; no CSP amplifies DOM-XSS risk.
  • <all_urls> host_permissions + content_scripts on every site grants persistent read/write access across all user browsing.
  • Developer uses numbered-alias gmail (businessinsider11@gmail.com) with no verified business domain or publisher badge.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands: amazon, youtube, reddit, netflix, twitch; dev domain gmail.com, not verified.
  • free_webmail_dev_numbered_alias store Developer email businessinsider11@gmail.com — numbered alias free webmail, no business website, not verified publisher.
  • privacy_policy_generic api Policy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • cve_jquery_xss crx jquery@3.4.1 bundled; CVE-2020-11022 + CVE-2020-11023 (moderate XSS); fixed_in 3.5.0. No CSP present.
  • dom_sink_innerhtml crx js/popup.js: innerHTML assigned from variable speed_display; no CSP and CVEs present → elevated DOM-XSS risk.
  • host_permissions_all_urls manifest <all_urls> in host_permissions + content_scripts_matches; scripting permission enables injection into every site.
  • no_csp manifest content_security_policy is null (MV3, so no MV2 penalty, but amplifies CVE/DOM-sink risk).
  • stale_20mo_with_cves store months_since_update=20; CVEs present and unfixed; no update addressing known vulnerabilities.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • storage low Stores speed preferences locally; minimal risk.
  • scripting medium Allows programmatic script injection into pages.
  • <all_urls> (host_permissions) high Full read/write access to every page the user visits.
  • <all_urls> (content_scripts) high Content scripts auto-inject into every origin, broad attack surface.

Pillar Scores

Permissions5.50
Reputation8.00
Network2.00
Webstore4.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure3.00

Scoring History

fsssiedxnfffd8138za'nfffd8138zsssiedx 5.44 Medium review 2026-08-27
sssiedn8fa879f9dp727562726963xsx 5.41 Medium review 2026-08-27
v3.6 6.06 High review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA 6c0e23a8f610…
Force block — not fired
Score recovered no
Elapsed 27.1s