Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

CSS Stacking Context inspector

apjeljpachdcjkgnamgppgfkmddadcki
Risk Score
5.35
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 9,000
Rating 3.8
Last updated 2024-08-16 (22 months ago)
Manifest version MV3
CSP present ❌ no
Developer dev@andreadev.it
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — does not scope to this extension at all (scope_extension=false, admits data collection and 3rd-party sharing).
  • Two eval_user_input findings via chrome.devtools.inspectedWindow.eval() with no CSP; code execution risk.
  • innerHTML DOM-XSS sink with no CSP present amplifies risk.
  • Broad host permissions (http://*/* + https://*/*) with content_scripts on <all_urls>; stale 22 months.
  • Extension last updated 22 months ago; triple-stale fingerprint concern (>18mo, MV3 but no CSP).

Evidence

  • privacy_policy_generic store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • eval_user_input_x2 crx Two files use chrome.devtools.inspectedWindow.eval(variable); +2.5 code quality per eval_user_input signal.
  • dom_sink_innerhtml_no_csp crx innerHTML sink with csp_present=false triggers FIX B amplifier → +2.0 code quality.
  • no_csp_mv3 manifest MV3 extension but content_security_policy is null; v2 fix (b) +2.0 network.
  • broad_host_permissions manifest http://*/* and https://*/* granted; content_scripts on <all_urls>. DeveloperTools discount applied (-1.5).
  • maintenance_stale store 22 months since update → maintenance score 6.0 (12-24mo band).
  • featured_by_google store is_featured_by_google=true → -2.0 reputation discount applied.
  • tail_attack_surface api install_perm_anomaly.tail_attack_surface=true → +1.0 webstore.

Permissions Breakdown

  • storage low Stores extension settings locally; low impact.
  • scripting medium Allows programmatic script injection into pages; medium risk.
  • http://*/* high Broad host access to all HTTP sites; high reach.
  • https://*/* high Broad host access to all HTTPS sites; high reach.
  • <all_urls> (content_scripts) high Content scripts injected on every URL; broad surface.

Pillar Scores

Permissions5.50
Reputation4.00
Network2.00
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality5.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA 1f66acb70540…
Force block — not fired
Score recovered no
Elapsed 28.5s