Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sidebarr - Bookmarks, Apps and more

afdfpkhbdpioonfeknablodaejkklbdn
Risk Score
6.58
Risk Level: High
Recommendation: 🚫 BLOCK
Category Productivity
Installs 10,000
Rating 4.4
Last updated 2025-10-03 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer romsiubsass@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall and install URL hijack both set — traffic-monetization pattern, no declared targets.
  • Privacy policy admits data collection + third-party sharing but not scoped to this extension → scores +10.
  • No CSP + multiple innerHTML sinks across 5 bundle files + function_constructor elevates DOM-XSS risk.
  • Free-webmail developer (gmail), no developer name, broad <all_urls> host access — low accountability.
  • 7 external JS hosts including chat.sidebarr.net and CDNs loaded from extension with no CSP guard.

Evidence

  • uninstall_url_hijack + install_url_hijack crx Both hijack flags set; targets null but pattern matches low-effort traffic-monetization (+3+2 Webstore).
  • privacy_policy scoped=false, data_collection=true, third_party_sharing=true api Policy admits collection+sharing without scoping to extension → Privacy pillar +10 (v3.5 rule D).
  • free-webmail dev, no developer name store romsiubsass@gmail.com, developer_name empty → Reputation +1.5+1.0 = floor near 7.
  • no CSP (csp_present=false, MV3) crx MV3 has strict-default but explicit null CSP; no MV2 +2 penalty; but worsens innerHTML sink severity.
  • dom_sink_innerhtml_userctrl × 5 files + no CSP crx csp_present==false triggers +2.0 per FIX B for each; consolidated to code_quality +2.5 signal.
  • function_constructor in contentScript.bundle.js crx new Function() constructor → +2.5 Code Quality.
  • 7 external JS hosts including sidebarr.org, chat.sidebarr.net crx >3 distinct registrable domains → Network +1.5.
  • verified_publisher=true, free-webmail email, no domain resolves check store Verified publisher discount capped at -1.0 (developer_domain_info null, cannot confirm domain).

Permissions Breakdown

  • storage low Local data persistence only.
  • bookmarks medium Read/write all browser bookmarks.
  • scripting medium Can inject scripts into pages; elevated with <all_urls>.
  • unlimitedStorage low No direct data exfil risk, just quota bypass.
  • favicon low Read site favicons only.
  • declarativeNetRequest medium Can intercept/block network requests.
  • tabs medium Can read tab URLs and metadata across all tabs.
  • alarms low Scheduling only, no direct data access.
  • <all_urls> (host) high Content scripts and scripting API reach every site the user visits.

Pillar Scores

Permissions7.00
Reputation7.00
Network6.50
Webstore8.50
Maintenance3.50
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:47
Listing SHA 42381d12943e…
Force block — not fired
Score recovered no
Elapsed