Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Phrasely - ChatGPT Writing Tool

adococdejjckhckfebefppmpefghoilg
Risk Score
5.28
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 827
Rating 5.0
Last updated 2024-11-21 (19 months ago)
Manifest version MV3
CSP present ❌ no
Developer kevinsbk@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Content script runs on <all_urls> — can read/modify page content on every site visited, despite only 'activeTab' in permissions[].
  • Privacy policy admits data collection AND third-party sharing but is not scoped to this extension (generic policy).
  • ChatGPT brand impersonation by unverified gmail developer with no developer name listed.
  • No CSP on MV3 extension with external host (editor.phrasely.app) — no header-level script constraint.
  • 19 months since last update; stale AI tool with broad content-script reach.

Evidence

  • content_scripts_matches=<all_urls> manifest Content script injected on all URLs despite narrow declared permissions[] — effective broad host access.
  • privacy_policy: data_collection+third_party_sharing+no_extension_scope api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
  • brand_mention impersonation store brand_mention.is_impersonation=true for 'chatgpt'; developer is gmail user, not verified owner.
  • developer_email gmail + no developer_name store Free-webmail dev (kevinsbk@gmail.com), developer_name empty, no business website identity.
  • csp_present=false manifest No content_security_policy declared; MV3 default applies but no explicit script constraint.
  • js_external_hosts=[editor.phrasely.app] crx Extension contacts external host editor.phrasely.app; not a known bad host but unverifiable data path.
  • months_since_update=19 store Last updated Nov 2024; 19 months stale — triggers 6-12 month maintenance band (+3.5) ... wait, 19mo = 12-24mo band.
  • verified_publisher=true + is_featured_by_google=true store Verified publisher and featured badges present, partially mitigating reputation; 0c cap applies (monetization/stale checks clean).

Permissions Breakdown

  • activeTab medium Grants access to the active tab on user action; low standalone risk.
  • content_scripts <all_urls> high Content script injected on ALL URLs gives broad page-read/write capability across every site.

Pillar Scores

Permissions3.50
Reputation6.50
Network2.50
Webstore5.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:15
Listing SHA 9d7608869398…
Force block — not fired
Score recovered no
Elapsed 22.0s