Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Google Drive

apdfllckaahabafndbhieahigkjlhalf
Risk Score
4.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs
Rating 4.5
Last updated 2020-10-24 (71 months ago)
Manifest version MV2
CSP present ❌ no
Developer docs-extension-support@google.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned MV2 extension: 71 months since last update, critically stale and unlikely to receive security patches.
  • No content_security_policy declared (MV2 + no CSP) adds +2.0 to network pillar per v2 calibration.
  • Privacy policy is Google's generic account policy — not scoped to this extension; data_collection and third_party_sharing both true per classifier.
  • Triple-stale fingerprint (>24mo + MV2 + no CSP) applies webstore penalty.
  • No JS files scanned (js_file_count=0) — extension may be a launcher/stub with reduced observable surface but still carries staleness risk.

Evidence

  • verified_publisher store Google verified publisher; developer domain google.com resolves, confirmed brand owner, not impersonation.
  • maintenance_critical store Last updated October 2020; 71 months since update — >36mo band scores 10.0 on maintenance pillar.
  • mv2_no_csp manifest MV2 extension with csp_present=false; +2.0 network penalty per v2 calibration rule (b).
  • privacy_policy_not_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • triple_stale_fingerprint store >24mo stale + MV2 + no CVEs; v2 calibration (c) applies +2.0 webstore, but no CVEs so partial trigger.
  • no_js_files crx js_file_count=0, js_files_scanned=0, code_findings_raw empty — code quality pillar scores 0.0.
  • cve_none crx cve_findings_raw is empty; CVE pillar = 0.0.
  • operator_cluster_clean api sibling_count=0; no operator cluster risk. No bad/monetization/affiliate hits in threat_intel.

Permissions Breakdown

  • clipboardRead medium Can read clipboard contents; moderate privacy risk for a productivity tool.
  • clipboardWrite low Write-only clipboard access; lower risk than read.
  • notifications low Can display browser notifications; minimal risk.

Pillar Scores

Permissions0.90
Reputation2.00
Network2.00
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-10 18:42
Listing SHA ded374311aa1…
Force block — not fired
Score recovered no
Elapsed