Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Video Player

ahgkbddhnkiclbikbaaoenljgpfbejhf
Risk Score
4.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 6,000
Rating 3.7
Last updated 2024-07-27 (23 months ago)
Manifest version MV3
CSP present ✅ yes
Developer chandler.stimson@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy, not scoped to this extension — admits data collection and 3rd-party sharing without extension context.
  • Developer is a free-webmail (gmail) individual with no verified business identity; unverifiable accountability.
  • Uninstall URL hijack flag set (uninstall_url_hijack=true); target URL not captured but pattern is monetization-linked.
  • Extension not updated in ~23 months; approaching stale threshold with no changelog.
  • Featured by Google but authored by anonymous gmail developer with below-average 3.7 rating.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • uninstall_url_hijack crx uninstall_url_hijack=true; target not captured. Webstore +3.0 per rubric.
  • developer_gmail store Developer email chandler.stimson@gmail.com — free webmail, no business domain, reputation starts at 5.0 +1.5.
  • is_featured_by_google store Featured badge present; applies -2.0 reputation discount.
  • maintenance_23mo store Last updated July 2024, ~23 months ago; falls in 12-24mo band → +6.0 maintenance.
  • csp_present_mv3 manifest CSP script-src 'self' 'wasm-unsafe-eval'; MV3 with CSP — no network penalty applied.
  • no_cve_no_code_findings crx cve_findings_raw=[], code_findings_raw=[], obfuscation_score=0.0 — code quality clean.
  • rating_below_4 store Rating 3.7; rating_count not provided, cannot confirm >=50 threshold, not applied.

Permissions Breakdown

  • storage low Stores local extension data; no cross-site or user data exfil risk alone.
  • contextMenus low Adds right-click menu items; minimal risk, no data access.

Pillar Scores

Permissions0.60
Reputation6.50
Network0.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA f0370f354077…
Force block — not fired
Score recovered no
Elapsed 21.2s