Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tab Manager by Workona

ailcmbgekjpnablpdkmaaccecekgdhlh
Risk Score
3.46
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 200,000
Rating 4.6
Last updated 2025-01-15 (17 months ago)
Manifest version MV3
CSP present ❌ no
Developer security@workona.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false with data_collection+third_party_sharing true — triggers +10.0 privacy pillar under v3.5 rule D.
  • History permission exposes full browsing history; no host_permissions but tabs+history is a sensitive combo.
  • No developer display name in listing; developer identity relies solely on email domain.
  • Extension is 17 months since last update — approaching stale threshold; no CVEs mitigate staleness concern.
  • No CSP declared (MV3 so no +2.0 network penalty, but absence noted with external JS host workona.com).

Evidence

  • privacy_policy_scope_mismatch api Policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount (follows recommended practices).
  • no_bad_hosts api threat_intel.bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no threat-intel hits.
  • code_findings_clean crx code_findings_raw=[], obfuscation_score=0.0 — no malicious code patterns detected.
  • cve_findings_clean crx cve_findings_raw=[] — no vulnerable bundled libraries.
  • maintenance_17mo store Last updated Jan 2025, months_since_update=17; scores +3.5 (6-12mo band edge, actually 12-24mo band).
  • developer_domain_resolves api workona.com resolves=true, looks_throwaway=false; established SaaS product domain.
  • no_operator_siblings api operator_cluster.sibling_count=0 — no sibling extension cluster risk.

Permissions Breakdown

  • contextMenus low Adds right-click menu entries; limited standalone risk.
  • history medium Can read full browsing history; sensitive but expected for tab manager.
  • tabs medium Access to tab URLs, titles, and navigation; core to stated function.
  • storage low Local extension data storage; low risk.
  • unlimitedStorage low Allows larger local storage quota; minimal incremental risk.

Pillar Scores

Permissions2.30
Reputation3.50
Network2.00
Webstore2.00
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:16
Listing SHA 2031b6c09af7…
Force block — not fired
Score recovered no
Elapsed 21.1s