Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Blocknative Gas Fee Estimator for Ethereum, Base, Arbitrum, and More

ablbagjepecncofimgjmdpnhnfjiecfm
Risk Score
2.55
Risk Level: Low
Recommendation: ✅ ALLOW
Category DeveloperTools
Installs 30,000
Rating 3.9
Last updated 2025-12-20 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer chrome@blocknative.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but does not scope to this extension and data_collection==false yields +9.0 privacy pillar — policy inadequate for enterprise.
  • No CSP declared (MV3 so no +2.0 network penalty, but no explicit script-src protection).
  • 5 distinct external JS hosts (all blocknative-owned) raises minor network breadth signal.
  • Rating 3.9 with unknown review count; no verified-publisher badge reduces reputation confidence.
  • Maintenance at 3-6 months boundary; continued monitoring recommended.

Evidence

  • permissions_minimal manifest Only 'storage' declared; no host_permissions, no content_scripts. Very low capability surface.
  • no_csp manifest content_security_policy is null. MV3 default applies; no explicit script-src hardening.
  • external_hosts_all_first_party crx 5 external hosts: api.blocknative.com, bnc-assets.com, docs.blocknative.com, explorer.blocknative.com, www.blocknative.com — all blocknative-owned.
  • privacy_policy_not_extension_scoped api Policy fetched (20 KB), scope_extension==false, data_collection==false → +9.0 privacy per FIX A.
  • no_bad_hosts_no_affiliate_no_monetization api threat_intel shows zero bad/affiliate/monetization hits; developer domain resolves, not throwaway.
  • featured_by_google store is_featured_by_google==true; no verified_publisher badge. Provides moderate trust signal.
  • no_code_findings_no_obfuscation crx code_findings_raw empty, obfuscation_score 0.0; 4 JS files scanned cleanly.
  • cve_none crx cve_findings_raw empty; no CVE exposure.

Permissions Breakdown

  • storage low Local key-value store only; no cross-origin or user-data exfil risk.

Pillar Scores

Permissions0.30
Reputation4.00
Network2.00
Webstore1.00
Maintenance1.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA 47c973f29edd…
Force block — not fired
Score recovered no
Elapsed 20.0s