Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

SignalHire - find email or phone number

aeidadjdhppdffggfgjpanbafaedankd
Risk Score
4.89
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 300,000
Rating 4.5
Last updated 2026-07-02
Manifest version MV3
CSP present ❌ no
Developer Support@SignalHire.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • cookies + scripting + <all_urls>: can intercept sessions and inject code on every site including LinkedIn profiles scraped at scale.
  • Privacy policy fetch failed (HTTP error); policy content unverifiable — treated as no effective policy.
  • No developer name in store listing reduces accountability; email domain resolves but no verified publisher badge.
  • Uninstall URL hijack flag set — extension registers a third-party URL on uninstall, a known monetization/tracking pattern.
  • MV3 without CSP declared; scripting+<all_urls> combo gives broad runtime injection capability across all visited pages.

Evidence

  • cookies+scripting+<all_urls> manifest Triple HIGH-risk combo: cookies, scripting, and <all_urls> enables full session+page interception on any site.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false due to HTTPError; policy content cannot be assessed — scored as +10.0.
  • uninstall_url_hijack crx uninstall_url_hijack==true; extension registers a callback URL on uninstall, a known monetization/tracking signal.
  • no_developer_name store developer_name is empty string; verified_publisher==false; is_featured_by_google==true applied as -2.0 rep discount.
  • content_scripts_narrow_vs_all_urls manifest content_scripts scoped to linkedin.com+signalhire.com but host_permissions=<all_urls>; scope mismatch +1.0 perm.
  • js_external_hosts_dev_tools crx js_external_hosts includes github.com, npms.io, react.dev, wxt.dev — appear to be dev-tool references, not live exfil.
  • install_count_300k store 300,000 installs with is_featured_by_google; high blast radius if compromised.
  • no_bad_hosts_no_cves api threat_intel.bad_host_hits empty, cve_findings_raw empty, obfuscation_score=0.0, code_findings_raw empty.

Permissions Breakdown

  • storage low Local data persistence; low standalone risk.
  • cookies high Can read/write cookies across all origins given <all_urls> host permission.
  • tabs medium Exposes URL and title of all open tabs; moderate privacy surface.
  • scripting high Allows arbitrary JS injection into any page via <all_urls>.
  • notifications low UI notifications only; no data-exfil risk on its own.
  • <all_urls> high Broad host access; combined with cookies+scripting enables full page+session interception.

Pillar Scores

Permissions7.00
Reputation4.00
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-10 05:41
Listing SHA 6c1281dc688a…
Force block — not fired
Score recovered no
Elapsed