Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

HTML validator

aofddmgnidinflambjlfkpboeamdldbd
Risk Score
5.15
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 558
Rating 5.0
Last updated 2024-11-19 (21 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@htmlvalidator.app
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack hook present — unusual for a developer tool, raises monetization/tracking concern.
  • Install URL hijack opens third-party page on install.
  • Privacy policy is Google's generic policy (unscoped, admits 3rd-party sharing) — not extension-specific.
  • No developer name; weak accountability for an extension with external host references.
  • 21-month staleness with innerHTML DOM sink and no CSP increases future exploit risk.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() present; target null but hook fires — webstore signal +3.0.
  • install_url_hijack crx onInstalled opens https://htmlvalidator.app/welcome — third-party URL redirect on install.
  • generic_privacy_policy store Policy URL is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) → +10.0 privacy.
  • no_developer_name store developer_name is empty string — no 'Offered by' accountability signal.
  • maintenance_stale store 21 months since last update (12-24mo band) → maintenance pillar +6.0.
  • dom_sink_innerhtml crx ace.js uses innerHTML from variable; no CSP present — elevated XSS risk → code quality +2.0.
  • no_csp manifest content_security_policy is null; MV3 has strict defaults but csp_present=false noted.
  • js_external_hosts crx Extension references example.com, github.com, htmlvalidator.app as external JS hosts.

Permissions Breakdown

  • storage low Local extension storage only; no host access granted.

Pillar Scores

Permissions0.30
Reputation6.00
Network0.00
Webstore8.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:24
Listing SHA b46a3acee5f3…
Force block — not fired
Score recovered no
Elapsed