Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

doqment PDF Reader

ajmcpdllaaklaocodbnllhkaflncmlog
Risk Score
3.08
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category ReaderMode
Installs 3,000
Rating 4.7
Last updated 2026-04-27 (2 months ago)
Manifest version MV3
CSP present ✅ yes
Developer shivaprsdv@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • Developer uses free webmail (gmail.com) with no verified business identity.
  • install_url_hijack flag set (install_url_target is null — may open a page on install).
  • CSP allows 'wasm-unsafe-eval' which is an elevated WebAssembly execution vector.
  • Small install base (3,000) reduces trust signal; no verified publisher badge.

Evidence

  • privacy_policy_generic store Policy URL is Google account privacy policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • developer_email_free_webmail store Developer email shivaprsdv@gmail.com is free webmail; no verified business domain; reputation raised.
  • install_url_hijack crx install_url_hijack=true but target is null; possible onInstalled redirect; no confirmed 3rd-party target.
  • featured_by_google store is_featured_by_google=true → -2.0 reputation discount applied.
  • csp_wasm_unsafe_eval manifest CSP script-src includes 'wasm-unsafe-eval'; appropriate for PDF renderer (pdfjs) but worth noting.
  • no_cve_findings crx cve_findings_raw=[] and js_libraries_detected=[]; no known vulnerable libraries bundled.
  • no_code_findings crx code_findings_raw=[] and obfuscation_score=0.0; code quality clean.
  • no_bad_host_hits api threat_intel bad_host_hits, affiliate_hits, monetization_hits all empty; js_external_hosts limited to drafts.csswg.org and github.com.

Permissions Breakdown

  • activeTab low Grants access only to the current tab on user action; narrow scope.
  • contextMenus low Adds right-click menu items; no data access.
  • scripting medium Can inject scripts into pages; paired with activeTab limits to user-triggered use.

Pillar Scores

Permissions1.30
Reputation6.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA 079fed043eb7…
Force block — not fired
Score recovered no
Elapsed 20.3s