Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Picture-in-Picture YouTube - Netflix and more

ahdijafdcpkcefendeaobodkfjcmphac
Risk Score
5.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 20,000
Rating 3.8
Last updated 2023-07-25 (35 months ago)
Manifest version MV3
CSP present ❌ no
Developer barreiro01919@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic Google Sites policy).
  • Brand impersonation: extension names YouTube and Netflix without verified ownership.
  • Developer is free-webmail only (gmail) with no business domain; unverifiable identity.
  • Extension last updated 35 months ago — approaching zombie status with 20K installs.
  • No CSP on MV3 extension; v2 calibration adds +2.0 to network pillar for MV2+no-CSP, but MV3 exempted — still no declared CSP.

Evidence

  • brand_impersonation store brands_mentioned=[youtube,netflix], confirmed_owner=false, is_impersonation=true.
  • free_webmail_developer store developer_email=barreiro01919@gmail.com; no business domain; identity unverifiable.
  • privacy_policy_generic_admits_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → v3.5(D) +10.0.
  • maintenance_stale store months_since_update=35; in 24-36mo band → +8.5.
  • no_bad_hosts_or_affiliates api threat_intel bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no malicious network signals.
  • no_code_findings crx code_findings_raw=[], obfuscation_score=0.0; code quality pillar 0.0.
  • featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount (Featured badge).
  • install_count_20k store 20,000 installs; >10K webstore signal +1.0.

Permissions Breakdown

  • activeTab low Grants access to current tab only on user gesture; low blast radius.
  • scripting medium Allows programmatic script injection into pages; medium risk without broad host perms.

Pillar Scores

Permissions1.30
Reputation7.50
Network2.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA e41343000801…
Force block — not fired
Score recovered no
Elapsed 20.5s