Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Read fast - Speed Reading Extension

pnffahcjemjliibgcafjpklgmbeknldi
Risk Score
5.63
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category ReaderMode
Installs 4,000
Rating 4.2
Last updated 2022-03-14 (51 months ago)
Manifest version MV3
CSP present ✅ yes
Developer mj.code.assist@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned: not updated in 51 months — high risk of unpatched vulnerabilities and supply-chain takeover.
  • 8 moderate CVEs in bundled jquery@1.9.0 and jquery-ui@1.10.0, both far below fixed versions.
  • Privacy policy is Google's generic account policy — not scoped to this extension at all.
  • Content script injected on <all_urls> gives DOM access across every site the user visits.
  • Developer uses free Gmail address with no verified business identity or domain.

Evidence

  • months_since_update=51 store Last updated March 2022; 51 months stale — maintenance pillar maxed at 10.0.
  • cve_moderate_x8 crx 8 moderate CVEs across jquery@1.9.0 and jquery-ui@1.10.0; none fixed in bundled versions.
  • privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, admits data_collection+third_party_sharing.
  • content_scripts_all_urls manifest content_scripts match <all_urls>, http://*/*, https://*/*ーbroad DOM reach on every page.
  • free_webmail_dev store Developer email mj.code.assist@gmail.com; no verified publisher, no business domain.
  • script_src_dynamic crx Dynamic script element creation in bundled jquery-1.9.0.min.js.
  • js_external_hosts crx References to bugs.jquery.com, jqueryui.com, www.mediacollege.com in extension JS.
  • triple_stale_fingerprint crx >24mo stale + CVEs present + MV3 (no v2 CSP penalty applied); stale+CVE combo amplifies risk.

CVE Exposures (8)

CVELibrarySeverity Fixed inSummary
CVE-2021-41182 jquery-ui@1.10.0 moderate 1.13.0 XSS in the `altField` option of the Datepicker widget in jquery-ui
CVE-2021-41184 jquery-ui@1.10.0 moderate 1.13.0 XSS in the `of` option of the `.position()` util in jquery-ui
CVE-2022-31160 jquery-ui@1.10.0 moderate 1.13.2 jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like in
CVE-2016-7103 jquery-ui@1.10.0 moderate 1.12.0 jQuery-UI vulnerable to Cross-site Scripting in dialog closeText
CVE-2021-41183 jquery-ui@1.10.0 moderate 1.13.0 XSS in `*Text` options of the Datepicker widget in jquery-ui
CVE-2019-11358 jquery@1.9.0 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.0 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • content_scripts:<all_urls> high Content script injected into every page — broad read/DOM access across all sites.

Pillar Scores

Permissions2.00
Reputation6.50
Network0.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality3.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA b0fb80f0efa6…
Force block — not fired
Score recovered no
Elapsed 32.0s