Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Image downloader - Imageye

agionbommeaifngbhincahgmoflcikhm
Risk Score
4.67
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 2,000,000
Rating 4.9
Last updated 2026-03-18 (6 months ago)
Manifest version MV3
CSP present ❌ no
Developer meaganamrach@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host access (<all_urls> + scripting + webRequest) enables full page reading and request interception on every site visited.
  • No CSP + dynamic script creation and new Function() constructors increase code-injection attack surface if extension is compromised.
  • Gmail developer identity with no business name; verified publisher badge present but identity transparency is limited.
  • Privacy policy fetched but does not scope to this extension nor disclose data collection — third-party silence flag raised.
  • Install/uninstall URL hijack redirects to imageye.net; 8 external JS hosts including www.gogather.mobi (unverified domain).

Evidence

  • broad_host_permissions manifest http://*/*, https://*/*, <all_urls> all declared; content_scripts also match all URLs.
  • webRequest_high_perm manifest webRequest paired with <all_urls> allows passive interception of all HTTP traffic.
  • no_csp crx content_security_policy is null; no CSP hardening on MV3 extension.
  • dynamic_script_and_new_function crx popup.js and 733.js use new Function() constructor and dynamic <script> creation.
  • gmail_dev_no_name store developer_email=meaganamrach@gmail.com; developer_name is empty string.
  • privacy_policy_not_extension_scoped api Policy fetched (45 KB) but scope_extension=false, data_collection=false; third_party_silence=true.
  • install_uninstall_url_hijack crx onInstalled → imageye.net/extension/installed/; onUninstalled → imageye.net/extension/uninstalled/.
  • verified_publisher_featured store verified_publisher=true, is_featured_by_google=true; partially mitigates reputation risk.

Permissions Breakdown

  • activeTab low Scoped to user-invoked tab; limited blast radius.
  • downloads medium Can write files to disk; core to stated function.
  • storage low Local preference storage; low standalone risk.
  • webRequest high Can observe all HTTP requests across all URLs; significant surveillance capability.
  • scripting high Arbitrary script injection into any page via broad host perms.
  • declarativeNetRequest medium Can block/redirect network requests; lower risk than webRequestBlocking.
  • sidePanel low UI surface only; no additional data access.
  • http://*/* high Broad host access covering all HTTP sites; amplifies scripting/webRequest risk.
  • https://*/* high Broad host access covering all HTTPS sites; amplifies scripting/webRequest risk.
  • <all_urls> high Redundant broad host grant; ensures no URL is excluded.

Pillar Scores

Permissions5.50
Reputation5.50
Network4.00
Webstore4.50
Maintenance0.00
Privacy9.00
Code Quality5.50
CVE Exposure0.00

Scoring History

fsssiedxnc28256feza'nc28256fezsssiedx 5.45 Medium review 2026-09-02
sssiedn5cc1c921dp727562726963xsx 5.54 Medium review 2026-09-02
sssiedn3c751cd8dp727562726963xsx 5.13 Medium review 2026-08-30
<fsssiedxi 4.97 Medium review 2026-08-22
fsssiedx<sssiedx 5.01 Medium review 2026-08-22
fsssiedxa'sssiedx 5.06 Medium review 2026-08-05
sssieddrubricxsx 5.21 Medium review 2026-08-05
v3.6 4.67 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA 7178e87636af…
Force block — not fired
Score recovered no
Elapsed 28.5s