Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Dark Theme for Google Chrome

annfbnbieaamhaimclajlajpijgkdblo
Risk Score
4.34
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 700,000
Rating 3.7
Last updated 2025-05-13 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@stefanvd.net
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension; admits data collection and 3rd-party sharing (D clause → +10.0 privacy pillar).
  • Brand impersonation: 'Google' mentioned in title but developer is not Google/verified owner (+2.0 reputation).
  • No CSP declared on MV3 extension with 800K installs; MV2 penalty not applicable but no observable surface area with large user base.
  • Maintenance: 13 months since last update (6-12 month band +3.5, borderline 12-24 +6.0 at 13mo → applied +6.0).
  • No developer name listed; email domain stefanvd.net resolves but dev identity unverified.

Evidence

  • privacy_policy_generic store Privacy URL points to myaccount.google.com generic policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true for 'google'; developer is not confirmed Google owner → +2.0 reputation.
  • verified_publisher store verified_publisher=true; discount applies but months_since_update=13 and generic policy trigger 0c cap at -1.0.
  • no_csp manifest content_security_policy=null on MV3; no high/medium CVEs so CVE amplifier does not apply.
  • stale_maintenance store months_since_update=13 falls in 12-24mo band → +6.0 maintenance pillar.
  • no_permissions manifest permissions=[], host_permissions=[], content_scripts_matches=[] — zero declared permissions; permissions pillar = 0.
  • no_js_surface crx js_file_count=0, code_findings_raw=[], obfuscation_score=0.0; code quality pillar = 0.
  • network_mv3_no_csp manifest MV3 with null CSP; no external hosts detected; +2.0 network for MV2 rule does not apply (MV3), base network = 2.0 for null CSP signal only.

Pillar Scores

Permissions0.00
Reputation5.50
Network2.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

v3.69910/"();}]9609 4.19 Medium review 2026-08-05
<th:t="${dfb}#foreach 2.79 Low review 2026-08-05
bfgx9157%C0%BEz1%C0%BCz2a%90bcxhjl9157 4.44 Medium review 2026-08-05
v3.6&n982078=v936949 4.02 Medium review 2026-08-05
dfb__${98991*97996}__::.x 3.49 Low review 2026-08-04
v3.6&n966919=v966108 4.23 Medium review 2026-08-04
%76%33%2E%36%39%36%37%31%22%28%29%3B%7D%5D%39%32%33%30 4.23 Medium review 2026-07-29
v3.6"sTYLe='zzz:Expre/**/SSion(1qFc(9921))'bad=" 4.07 Medium review 2026-07-29
v3.6"onmouseover=1qFc(95672)" 4.31 Medium review 2026-07-29
dfb{{98991*97996}}xca 4.29 Medium review 2026-07-29
bfgx3026%C0%BEz1%C0%BCz2a%90bcxhjl3026 4.29 Medium review 2026-07-29
dfb[[${98991*97996}]]xca 3.82 Low review 2026-07-29
<%={{={@{#{${dfb}}%> 4.27 Medium review 2026-07-29
'"()&%<zzz><ScRiPt >1qFc(9856)</ScRiPt> 4.63 Medium review 2026-07-29
v3.6&n995608=v948472 4.03 Medium review 2026-07-29
v3.6 4.34 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA 065e7aaef333…
Force block — not fired
Score recovered no
Elapsed 20.4s