Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Symvek Shield: Privacy Score & Tracker Blocker

apgiipaoknpflkngmeibegmbijppmpog
Risk Score
3.87
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category PrivacyTool
Installs 5
Rating
Last updated 2026-06-09
Manifest version MV3
CSP present ❌ no
Developer hello@symvek.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • No developer name listed and no verified publisher badge; low accountability for a privacy-tool claiming broad host access.
  • webRequest + <all_urls> + content_scripts on all URLs gives full browsing observation capability to unknown developer.
  • Privacy policy URL points to Chrome Web Store listing page, not a real policy; classified as scoped but lacks retention disclosure.
  • Only 5 installs with HIGH-tier permissions flagged by install_perm_anomaly — small-install/high-perm tail-attack-surface signal.
  • MV3 + no CSP: no CSP penalty applies (MV3 default), but api.symvek.com outbound contact is unverifiable without code findings.

Evidence

  • high_perm_broad_host manifest webRequest + <all_urls> + content_scripts on all URLs; justified-broad discount applied for PrivacyTool category.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity visible; +1.0 reputation penalty.
  • privacy_policy_is_store_page store privacy_policy_url resolves to the CWS listing itself, not a standalone policy; retention==false.
  • small_install_high_perm api install_perm_anomaly.small_install_high_perm==true; 5 installs with HIGH-tier permissions.
  • outbound_host crx js_external_hosts: [api.symvek.com]; single dev-controlled domain, no bad-host hits.
  • third_party_sharing_admitted api privacy_policy_classification.third_party_sharing==true; retention==false; privacy pillar elevated.
  • no_verified_publisher store verified_publisher==false, is_featured_by_google==false; no trust discounts applicable.
  • cve_clean crx cve_findings_raw empty; code_findings_raw empty; obfuscation_score 0.0.

Permissions Breakdown

  • storage low Standard local storage for settings/state.
  • tabs medium Can read tab URLs and metadata across all open tabs.
  • declarativeNetRequest medium Core function for tracker blocking; appropriate for category.
  • declarativeNetRequestFeedback medium Allows reading which rules fired; minor data-exposure risk.
  • webRequest high Can observe all HTTP requests on <all_urls>; broad surveillance capability.
  • webNavigation medium Tracks navigation events; combined with tabs increases browsing visibility.
  • <all_urls> (host_permission) high Content scripts inject into every site; pairs with webRequest for full browsing scope.

Pillar Scores

Permissions5.50
Reputation6.00
Network4.00
Webstore2.50
Maintenance0.00
Privacy6.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA 6f8c2920820a…
Force block — not fired
Score recovered no
Elapsed 24.5s