Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Apollo.io: Free B2B Phone Number & Email Finder

alhgpfoeiimagjlnfekdhkjlkiomcapa
Risk Score
4.04
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 1,000,000
Rating 4.7
Last updated 2026-06-08
Manifest version MV3
CSP present ✅ yes
Developer support@apollo.io
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched and scoped to company not extension; admits data collection and third-party sharing without extension-specific scope — scores max privacy risk.
  • Broad *://*/* host permission with scripting enables script injection on every website user visits.
  • 6 innerHTML DOM-XSS sinks across background, panel, and vendor bundles; CSP present but connect-src is broad.
  • No developer name listed in store despite verified publisher status; developer_name field empty.
  • tabs + webNavigation + broad host = full browsing history observable by extension on all pages.

Evidence

  • broad_host_permission manifest *://*/* host permission grants access to every website; combined with scripting and tabs raises capability risk.
  • privacy_policy_no_extension_scope api Policy fetched (163k chars); scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
  • dom_xss_sinks crx 6 innerHTML-from-variable findings across background, panel, vendor, and LinkedIn iframe bundles.
  • verified_publisher_featured store Verified publisher + featured by Google; applied discounts capped per 0c (no stale/CVE/domain issues here).
  • csp_broad_connect_src manifest connect-src lists 18+ endpoints including Twilio, Amplitude, NewRelic, Pusher, customer.io, Sentry.
  • no_bad_hosts_no_affiliate api threat_intel shows no bad_host_hits, no affiliate_hits, no monetization_hits; developer domain resolves.
  • recently_updated store Last updated June 8 2026; months_since_update=0; maintenance risk is minimal.
  • no_cve_findings crx cve_findings_raw is empty; no known-vulnerable bundled libraries detected.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; limited risk.
  • notifications low Can show desktop notifications; minor user-annoyance risk.
  • scripting medium Can inject scripts into pages; elevated when paired with broad host access.
  • storage low Local/sync storage; no direct exfil path.
  • tabs medium Can read tab URLs and titles across all tabs.
  • webNavigation medium Can observe full navigation events across all pages.
  • sidePanel low Displays sidebar UI; no direct data-access risk.
  • *://*/* high Broad host permission; allows script injection and data access on every site.

Pillar Scores

Permissions5.80
Reputation2.00
Network3.50
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:17
Listing SHA 57bf9acf924b…
Force block — not fired
Score recovered no
Elapsed 39.1s