Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Diigo Web Collector - Capture and Annotate

pnhplgjpclknigjpccbcnmicgcieojbh
Risk Score
5.72
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Productivity
Installs 200,000
Rating 4.6
Last updated 2024-06-30 (24 months ago)
Manifest version MV3
CSP present ✅ yes
Developer developer@diigo.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • 9 moderate CVEs across jquery@1.8.0 and jquery@2.1.0 (both far below fixed version), amplified by DOM-XSS sinks in same codebase.
  • eval() and new Function() in content scripts running on <all_urls> create direct code-execution surface on every page visited.
  • Privacy policy fetched but scope_extension==false with data_collection==true and third_party_sharing==true — maps to +10.0 under v3.5 rule D.
  • Stale extension (24 months since update) with multiple CVEs and MV3; triple-stale fingerprint applies.
  • cookies permission combined with <all_urls> host access and scripting on all sites creates broad credential/session-token exfil surface.

Evidence

  • cve_jquery_1.8.0 crx 5 moderate CVEs in jquery@1.8.0; fixed_in up to 3.5.0. Library is 13 major versions behind.
  • cve_jquery_2.1.0 crx 4 moderate CVEs in jquery@2.1.0; fixed_in up to 3.5.0. Also well below fixed version.
  • eval_user_input crx js/content/diigolet.js: devil:function(a){return eval(a)} — direct eval of variable in content script.
  • function_constructor crx Multiple new Function() calls in dragresize.js and bundled jquery; code-execution risk.
  • dom_sink_innerhtml_userctrl crx 6 files with unguarded innerHTML assignments; CVEs present and no inline CSP on pages.
  • privacy_policy_generic store Policy at diigo.com/privacy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • maintenance_stale_24mo store Last updated June 2024; months_since_update=24. Triple-stale (>24mo + CVEs + MV3-but-old) applies.
  • verified_publisher_featured store Verified publisher + Google Featured; discounts capped at -1.0 due to monetization_hits and stale age (v3.5 rule E/0c).

CVE Exposures (9)

CVELibrarySeverity Fixed inSummary
CVE-2012-6708 jquery@1.8.0 moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2019-11358 jquery@1.8.0 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.8.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-7656 jquery@1.8.0 moderate 1.9.0 Cross-Site Scripting in jquery
CVE-2015-9251 jquery@1.8.0 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery
CVE-2019-11358 jquery@2.1.0 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.0 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.0 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • contextMenus low Adds right-click menu items; minimal risk.
  • tabs medium Can read tab URLs and titles across all open tabs.
  • cookies high Access to cookies; combined with <all_urls> host perm raises exfil risk.
  • storage low Local extension storage only; low risk.
  • scripting high Programmatic script injection into pages; broad host perm amplifies this.
  • pageCapture medium Can capture full page content as MHTML; sensitive data capture possible.
  • <all_urls> (host) high Grants access to every site visited; amplifies cookies and scripting risks.

Pillar Scores

Permissions7.50
Reputation2.00
Network3.50
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality7.50
CVE Exposure7.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 08:05
Listing SHA 29819e7badaf…
Force block — not fired
Score recovered no
Elapsed 41.2s