Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Vieu Chrome Extension - Get introduced to your buyers

bamkikhlhhnpdkehbjpepjkjgcdcdlfi
Risk Score
4.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 187
Rating 5.0
Last updated 2026-08-03
Manifest version MV3
CSP present ✅ yes
Developer valet@vieu.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy not scoped to this extension but admits data collection and third-party sharing — scores maximum privacy risk.
  • Broad https://*/*ost permission with content scripts injected on all HTTPS sites creates high capability reach.
  • Third-party backend api.cloud.seeqe.com is unrelated domain to vieu.com — unclear data controller relationship.
  • yandex.com listed as external JS host and search engine contact raises unexplained data routing concern.
  • No developer name listed despite verified publisher status; install count of 187 limits reputation signal.

Evidence

  • privacy_policy_not_extension_scoped api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → D rule triggers +10.0 privacy.
  • broad_host_permission manifest host_permissions includes https://*/*; content_scripts also match https://*/*ery HTTPS page.
  • third_party_backend manifest api.cloud.seeqe.com appears in both host_permissions and js_external_hosts; domain differs from vieu.com.
  • yandex_external_host crx yandex.com in js_external_hosts and threat_intel.search_engines_seen; unexpected for a B2B sales tool.
  • verified_publisher store verified_publisher=true; domain resolves, not throwaway; no monetization/affiliate hits.
  • small_install_high_perm api install_perm_anomaly.small_install_high_perm=true; 187 installs with broad https://*/*ost access.
  • cve_findings_empty crx No CVEs detected; no bundled vulnerable JS libraries found.
  • code_findings_empty_no_obfuscation crx code_findings_raw=[]; obfuscation_score=0.0; 12 JS files scanned cleanly.

Permissions Breakdown

  • storage low Local data persistence; standard low-risk permission.
  • activeTab low Scoped to user-invoked tab; limited blast radius.
  • offscreen low Offscreen document; low risk without other high-risk combos.
  • tabs medium Access to tab URLs and metadata across all tabs.
  • windows low Window enumeration; minor privacy exposure.
  • https://*/* high Broad host access covering all HTTPS sites; high capability surface.
  • https://api.cloud.seeqe.com/* medium Explicit API endpoint; third-party backend not clearly same-org as vieu.com.

Pillar Scores

Permissions5.50
Reputation3.00
Network3.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:26
Listing SHA 5f1f11ef88d5…
Force block — not fired
Score recovered no
Elapsed