Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Bookmark Favicon Changer

acmfnomgphggonodopogfbmkneepfgnh
Risk Score
5.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 40,000
Rating 4.0
Last updated 2025-01-19 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer sonthakit@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • webRequest + scripting + <all_urls>: can intercept and modify all browser traffic and inject code into any page.
  • Privacy policy is Google's generic account policy — does not scope data collection to this extension at all.
  • Developer uses free Gmail with no verifiable business identity; no verified publisher badge.
  • Hex-string density in common.js suggests partial obfuscation; external host www.webtoolkit.info loads JS.
  • No CSP declared (MV3 exemption applies, but combined with broad permissions increases attack surface on compromise).

Evidence

  • broad_host_permissions manifest <all_urls> host permission paired with webRequest and scripting.
  • generic_privacy_policy store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • free_webmail_developer store Developer email sonthakit@gmail.com with no business domain; no verified publisher.
  • hex_obfuscation crx common.js contains dense hex escape sequences flagged as likely obfuscation.
  • external_js_host crx JS loaded from www.webtoolkit.info — third-party domain outside dev's control.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • maintenance_stale store Last updated January 2025; 17 months since update at scoring time.
  • no_cve_findings crx cve_findings_raw is empty; no known vulnerable libraries detected.

Permissions Breakdown

  • tabs medium Access to tab URLs and metadata.
  • bookmarks medium Read/write all bookmarks — core function.
  • downloads medium Can trigger file downloads; combined with scripting raises risk.
  • storage low Local data persistence only.
  • webRequest high Observe all network requests across all URLs.
  • unlimitedStorage low No user-data risk, just quota.
  • offscreen low Allows background DOM operations; low standalone risk.
  • scripting high Inject scripts into any page via <all_urls> host permission.
  • favicon low Read favicon URLs — matches stated purpose.
  • <all_urls> high Broad host access amplifies webRequest and scripting to all sites.

Pillar Scores

Permissions7.50
Reputation6.50
Network4.00
Webstore3.50
Maintenance3.50
Privacy10.00
Code Quality1.50
CVE Exposure0.00

Scoring History

fsssiedxa'sssiedx 5.75 Medium review 2026-08-20
sssieddrubricxsx 5.88 Medium review 2026-08-20
v3.6 5.72 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA 999118e365a3…
Force block — not fired
Score recovered no
Elapsed 24.3s