Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

PerfectPost: makes Linkedin 10x better

bagapgnffhmfccajdbbjcgalkphdjccn
Risk Score
4.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 20,000
Rating 4.8
Last updated 2026-05-31 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer contact@perfectpost.fr
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and third-party sharing.
  • No CSP + 4x innerHTML DOM-XSS sinks on linkedin.com elevates DOM-XSS risk to content-script context.
  • Developer domain perfectpost.fr does not resolve; verified-publisher discount capped per invariant 0c.
  • Brand impersonation flag: LinkedIn brand mentioned, developer not confirmed owner, not a verified LinkedIn partner.
  • webRequest permission on linkedin.com enables observation of all LinkedIn network traffic including auth tokens.

Evidence

  • privacy_policy_generic_google store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5 rule D).
  • no_csp_plus_innerhtml_sinks crx csp_present=false AND 4 dom_sink_innerhtml_userctrl findings → FIX B applies: each counts as +2.0 code quality (capped at 10).
  • developer_domain_not_resolving api perfectpost.fr resolves=false; verified-publisher discount capped at -1.0 per invariant 0c.
  • brand_impersonation store brand_mention.is_impersonation=true for LinkedIn; verified_publisher=true so +1.0 Reputation (v3.2 rule 9).
  • uninstall_url_hijack crx uninstall_url_hijack=true; +3.0 Webstore per rubric.
  • js_external_hosts_count crx 12 distinct external hosts including api.mixpanel.com (telemetry), github.com, gsap.com, mui.com → >3 distinct domains +1.5 Network.
  • react_v16_13_1_bundled crx React 16.13.1 bundled; no CVE hits in cve_findings_raw so no CVE score added.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discount capped at -1.0 due to non-resolving dev domain.

Permissions Breakdown

  • alarms low Scheduling only; minimal abuse surface.
  • storage low Local data persistence; standard for productivity tools.
  • tabs medium Can read tab URLs and titles across browsing session.
  • webRequest high Can observe all network requests on in-scope hosts; elevated risk.
  • *://*.linkedin.com/* medium Scoped to LinkedIn only; matches stated function but accesses sensitive professional data.

Pillar Scores

Permissions4.50
Reputation4.00
Network4.50
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA 28b9a0c4af5b…
Force block — not fired
Score recovered no
Elapsed 29.5s