Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Run Whats Sender

pokenhlckhaoenaipopidoddgdbhlegh
Risk Score
7.38
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 134
Rating
Last updated 2024-06-29 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer sales@runwhats.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • browsingData + broad host access (<all_urls>) allows full browsing data deletion and page content exfil.
  • Developer domain runwhats.com does not resolve; privacy policy unfetchable — no accountability.
  • Three medium CVEs in bundled jquery@1.9.1 (XSS); no CSP amplifies exploitability.
  • 26 months without update; stale extension with high-capability permissions is a supply-chain risk.
  • Dynamic script injection + innerHTML sink with no CSP creates DOM-XSS attack surface.

Evidence

  • broad_host_access manifest http://*/* and https://*/* grant read/modify on all pages; paired with browsingData and scripting.
  • developer_domain_no_resolve api threat_intel: runwhats.com resolves=false; privacy policy fetch failed with ConnectionError.
  • privacy_policy_unfetchable api privacy_policy_classification.fetched=false; cannot assess data handling commitments.
  • cve_medium_x3_jquery crx jquery@1.9.1 carries CVE-2015-9251, CVE-2019-11358, CVE-2020-11023 (all XSS, fixed in >=3.5.0).
  • no_csp_with_cve manifest csp_present=false; CVE amplifier applies — jquery XSS CVEs with no CSP protection.
  • stale_extension store Last updated June 2024; 26 months_since_update triggers +8.5 maintenance score.
  • dynamic_script_injection crx script_src_dynamic in app/app.js and app/content.js; dom_sink_innerhtml in content.js.
  • tail_attack_surface api install_perm_anomaly: 134 installs + high-tier permissions (small_install_high_perm=true).

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab — limited risk alone.
  • scripting high Programmatic script injection into pages; paired with broad host access.
  • background low Persistent service worker; enables long-running operations.
  • browsingData high Can delete cookies, cache, history — destructive capability.
  • tabs medium Access to tab URLs/titles across all open tabs.
  • http://*/* high Broad HTTP host access — can read/modify any HTTP page.
  • https://*/* high Broad HTTPS host access — can read/modify any HTTPS page.

Pillar Scores

Permissions8.00
Reputation6.00
Network5.50
Webstore5.00
Maintenance8.50
Privacy10.00
Code Quality6.00
CVE Exposure4.50

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 04:57
Listing SHA 41ac625f6217…
Force block — not fired
Score recovered no
Elapsed