Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Music Mode for YouTube™

abbpaepbpakcpipajigmlpnhlnbennna
Risk Score
4.23
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 70,000
Rating 4.6
Last updated 2026-03-23 (3 months ago)
Manifest version MV3
CSP present ❌ no
Developer thunderarea.np@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension; data practices completely undisclosed.
  • Brand impersonation: YouTube™ trademark in name without verified ownership; developer is gmail-only individual.
  • Free-webmail developer (gmail) with no business domain; low accountability and transfer risk.
  • install_url_hijack: onInstalled opens pages/options.html — minor but indicative of low-hygiene practices.
  • DOM-XSS sink (innerHTML from variable) with no CSP; exploitable if input ever reaches user-controlled data.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; YouTube™ trademark used; developer is gmail individual, not YouTube/Google.
  • generic_privacy_policy store Privacy URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email thunderarea.np@gmail.com; no business domain; domain_age_ct not queried.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens pages/options.html (internal page, low severity but present).
  • dom_xss_sink crx dom_sink_innerhtml_userctrl in content_popup/content.js; no CSP present; DOM-XSS risk on YouTube pages.
  • no_csp manifest content_security_policy is null; MV3 has strict defaults but no explicit CSP increases XSS sink risk.
  • featured_by_google store is_featured_by_google=true; partially offsets brand/reputation risk.
  • installs_reach store 70,000 installs on YouTube-scoped content scripts; blast radius limited to YouTube domains.

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata; enables tracking of visited YouTube pages.
  • declarativeNetRequest medium Can block/redirect network requests; scoped to YouTube domains here, moderate risk.
  • storage low Local data persistence only; standard for storing user preferences.
  • unlimitedStorage low Removes storage quota cap; low direct harm but could store large amounts of data.
  • content_scripts: *://www.youtube.com/* (and related) medium Runs JS on all YouTube pages; scoped to YouTube only, matches stated function.

Pillar Scores

Permissions2.30
Reputation7.00
Network0.00
Webstore5.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA f382f59f2b21…
Force block — not fired
Score recovered no
Elapsed 24.8s