Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Docs

aohghmighlieiainnegkcijnfilokake
Risk Score
4.83
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs
Rating 4.3
Last updated 2017-10-12 (107 months ago)
Manifest version MV2
CSP present ❌ no
Developer docs-extension-support@google.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extension last updated October 2017 (107 months ago) — severely abandoned, unpatched against any browser changes or vulnerabilities.
  • Privacy policy is Google's generic account policy, not scoped to this extension; data_collection and third_party_sharing both true with no extension-specific scope.
  • MV2 with no CSP: +2.0 Network penalty applies per v2 calibration rule (b).
  • Triple-stale fingerprint: >24mo stale + MV2 + no CSP triggers webstore anomaly signal.
  • No developer name listed in store; policy is generic, reducing transparency accountability.

Evidence

  • verified_publisher store Google verified publisher; developer email docs-extension-support@google.com on google.com domain which resolves and is 20+ years old.
  • maintenance_stale store Last updated October 2017, 107 months ago — worst maintenance band (>36mo), zombie booster does not apply (install_count unknown).
  • privacy_policy_generic api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true: generic Google policy, not scoped to this extension.
  • mv2_no_csp manifest Manifest V2 with null CSP. v2 calibration +2.0 Network penalty applied.
  • triple_stale_fingerprint manifest >24mo stale + MV2 + no CVEs (CVE empty so no amplifier); v2 fix (c) +2.0 Webstore applied.
  • zero_permissions manifest No declared permissions, host_permissions, or content_scripts. Minimal capability surface.
  • js_external_host crx Single external JS host: docs.google.com — Google-owned, low risk.
  • code_clean crx code_findings_raw empty, obfuscation_score 0.0, 1 JS file scanned. No malicious signals detected.

Pillar Scores

Permissions0.00
Reputation2.00
Network2.00
Webstore1.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-10 18:42
Listing SHA 7e559caee06f…
Force block — not fired
Score recovered no
Elapsed