Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

LMV Developer Tools

annfeccochdhninjikchkkioemhdpjje
Risk Score
5.79
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 414
Rating 5.0
Last updated 2022-02-14 (52 months ago)
Manifest version MV3
CSP present ❌ no
Developer lmv.developer.tools@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned extension: last updated 52 months ago, no maintenance signal.
  • Privacy policy is Google's generic account policy — no extension-specific scope, admits data collection and 3rd-party sharing.
  • Content scripts injected on all HTTP/HTTPS URLs despite minimal declared permissions.
  • Gmail developer identity, no verified publisher, no business domain.
  • Google Tag Manager endpoint in JS external hosts suggests telemetry reporting from all visited pages.

Evidence

  • stale_extension store Last updated February 14, 2022 — 52 months ago. No changelog or active maintenance indicators.
  • generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • broad_content_scripts manifest content_scripts_matches covers http://*/* and https://*/* — all pages — despite only storage+activeTab declared.
  • gmail_developer store Developer email lmv.developer.tools@gmail.com; no verified publisher badge; no business domain.
  • monetization_host crx www.googletagmanager.com present in JS external hosts — telemetry/analytics endpoint.
  • function_constructor crx new Function('return this') found in bundled chunk; low risk in isolation but warrants note.
  • no_csp manifest content_security_policy is null for MV3 extension; reduces isolation guarantees.
  • autodesk_domain crx lmv.ninja.autodesk.com in external hosts — suggests Autodesk LMV viewer tooling, consistent with DeveloperTools category.

Permissions Breakdown

  • storage low Local key-value store only; no cross-site data exposure.
  • activeTab low Grants access to current tab only on explicit user action.
  • content_scripts http://*/* https://*/* medium Broad content-script injection into all HTTP/HTTPS pages elevates reach significantly.

Pillar Scores

Permissions2.30
Reputation6.50
Network3.00
Webstore3.50
Maintenance10.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA e89c769bdf44…
Force block — not fired
Score recovered no
Elapsed 20.0s