Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Web Sticky Notes

afhkepcebfdbgkjipfpoipmckfopphek
Risk Score
4.32
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 5,000
Rating 4.0
Last updated 2023-06-12 (36 months ago)
Manifest version MV3
CSP present ❌ no
Developer hi@hacknship.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • Extension not updated in 36 months (exact stale threshold); zombie-state increases supply-chain risk.
  • External JS hosts include tngk.link (short-link service) and api.gumroad.com; no CSP to constrain them.
  • No content_security_policy on MV3; less critical than MV2 but external hosts lack CSP restriction.
  • Developer identity is small indie (hacknship.com); no verified-publisher badge raises accountability concerns.

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com — Google's own account policy. scope_extension=false, data_collection=true, third_party_sharing=true.
  • maintenance_stale store Last updated June 2023; months_since_update=36. Maximum maintenance penalty applied.
  • external_hosts crx js_external_hosts: api.gumroad.com, tngk.link, null. tngk.link is a URL-shortener/redirect service.
  • no_csp manifest content_security_policy is null; MV3 default applies but external host contacts are unconstrained by policy.
  • featured_by_google store is_featured_by_google=true; partial reputation credit applied.
  • no_bad_hosts_no_cves crx bad_host_hits=[], cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0. No malicious indicators found.
  • operator_cluster_clean api sibling_count=0; no related suspicious extensions under same fingerprint.
  • developer_domain_resolves api hacknship.com resolves, looks_throwaway=false. Wayback check failed (fetch_error).

Permissions Breakdown

  • activeTab low Activates only on user gesture; limited scope.
  • storage low Local data persistence; no exfil risk alone.
  • tabs medium Can read tab URLs and titles; moderate privacy surface.

Pillar Scores

Permissions1.30
Reputation4.50
Network2.00
Webstore0.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA ed8a9ff0ab6c…
Force block — not fired
Score recovered no
Elapsed 19.4s