Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Remover

alepdkfogdlaehmdljdlipmomgipcbom
Risk Score
5.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 22
Rating 4.8
Last updated 2025-02-18 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer appgoogloc@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Google brand impersonation: 'googloc' mimics Google, dev is unverified gmail user with no confirmed ownership.
  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Startup page override redirects browser to googloc.com — a non-Google site masquerading as Google.
  • innerHTML sink in content_script.js creates DOM-XSS risk; no CSP present to mitigate.
  • 18-month stale extension with only 22 installs — tail-attack-surface, low accountability, free-webmail dev.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; 'google' mentioned, dev is gmail user 'googloc', confirmed_owner=false.
  • startup_page_override manifest chrome_settings_overrides.startup_pages=['https://googloc.com/start'] — hijacks browser startup to unverified domain.
  • generic_privacy_policy store Privacy URL is Google Account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • dom_xss_sink crx innerHTML assigned from variable in content_script.js; csp_present=false amplifies risk.
  • free_webmail_dev store Developer email appgoogloc@gmail.com — free webmail, no verified business, no publisher badge.
  • stale_extension store months_since_update=18; maintenance score elevated to 6.0 (6-12 month band boundary).
  • external_js_host crx js_external_hosts includes stackoverflow.com and www.googloc.com — unexpected external host for this extension.
  • no_csp manifest content_security_policy=null; MV3 default CSP applies but no explicit policy hardening declared.

Permissions Breakdown

  • chrome_settings_overrides.startup_pages medium Overrides browser startup page to googloc.com — medium-risk browser setting hijack.

Pillar Scores

Permissions2.00
Reputation8.50
Network0.00
Webstore6.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:38
Listing SHA 429baec63061…
Force block — not fired
Score recovered no
Elapsed