Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Slides

aapocclcgogkmnckokdopfmhonfmgoek
Risk Score
4.12
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs
Rating 4.2
Last updated 2017-10-12 (107 months ago)
Manifest version MV2
CSP present ❌ no
Developer docs-extension-support@google.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extremely stale: last updated October 2017 (107 months), MV2, no CSP — abandoned by maintainer.
  • Privacy policy is Google's generic account policy; scope_extension=false and data_collection=true with third_party_sharing=true.
  • MV2 with no CSP: +2.0 network penalty applied per v2 calibration rule (b).
  • No developer display name listed in store despite being a Google extension.
  • Triple-stale fingerprint (>24mo + MV2 + no CSP) signals unmanaged legacy extension.

Evidence

  • verified_publisher store Google verified publisher; developer email docs-extension-support@google.com on google.com domain.
  • maintenance_stale store Last updated October 2017, 107 months ago — >36 months stale, maintenance pillar capped at 10.0.
  • no_csp manifest csp_present=false on MV2 extension; +2.0 network penalty per v2 rule (b).
  • privacy_policy_generic api Policy is Google account-level; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
  • no_permissions manifest permissions[], host_permissions[], content_scripts_matches[] all empty — minimal declared capability.
  • js_external_host crx Single external JS host: docs.google.com — Google-controlled, no bad-host hits.
  • no_code_findings crx code_findings_raw empty, obfuscation_score=0.0, no CVEs detected.
  • triple_stale_fingerprint store >24mo stale + MV2 + no CSP; v2 calibration fix (c) does not add webstore score (no CVEs), but maintenance is maxed.

Pillar Scores

Permissions0.00
Reputation2.00
Network2.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Operator Siblings (1)

Other extensions sharing this developer's compound fingerprint:

Scoring History

zzz 4.04 Medium review 2026-09-10
sectest9002 4.07 Medium review 2026-09-10
sectest4471 4.16 Medium review 2026-09-10
v3.6 4.12 Medium review 2026-09-10

Bookkeeping

Rubric v3.6
Scored at 2026-09-10 18:43
Listing SHA 4d7e65cbeb47…
Force block — not fired
Score recovered no
Elapsed