Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Clothing Brand Name Generator

abbngaojehjekanfdipifimgmppiojpl
Risk Score
4.76
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 29
Rating
Last updated 2024-12-08 (20 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@clothingbrandnamegenerator.app
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own account policy — not scoped to this extension; admits data collection and 3rd-party sharing (+10.0 privacy).
  • No developer name listed and domain does not resolve, undermining accountability.
  • Install-URL hijack opens clothingbrandnamegenerator.app/welcome on install; uninstall-URL hijack also set.
  • Developer domain (clothingbrandnamegenerator.app) does not resolve — dead or throwaway.
  • 20 months since last update (6-12mo band) with no governance or changelog visible.

Evidence

  • privacy_policy_generic store Privacy URL is Google's account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • install_url_hijack manifest install_url_hijack=true; target=https://clothingbrandnamegenerator.app/welcome → +2.0 webstore.
  • uninstall_url_hijack manifest uninstall_url_hijack=true, target=null → +3.0 webstore (numbered-alias / hijack cluster).
  • developer_domain_not_resolving api threat_intel.developer_domain_info.resolves=false; domain clothingbrandnamegenerator.app dead → caps verified-publisher discount (N/A here) and raises reputation risk.
  • no_developer_name store developer_name is empty string → +1.0 reputation (no 'Offered by').
  • js_external_host_acylt crx flightschool.acylt.com in js_external_hosts — acylt is a known email/push marketing platform, not core function.
  • maintenance_stale store months_since_update=20 → 12-24mo band → +6.0 maintenance.
  • csp_absent_mv3 manifest csp_present=false on MV3; no amplifier applied (MV3 strict default), but no CSP declared.

Permissions Breakdown

  • storage low Local key-value storage; no cross-origin data exposure by itself.

Pillar Scores

Permissions1.00
Reputation7.50
Network2.00
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:09
Listing SHA 8fbd191f0941…
Force block — not fired
Score recovered no
Elapsed