Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Zoom Page WE

bcdjhkphgmiapajkphennjfgoehpodpk
Risk Score
6.03
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Accessibility
Installs 10,000
Rating 4.1
Last updated 2023-04-29 (38 months ago)
Manifest version MV3
CSP present ❌ no
Developer dw-dev@gmx.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • 38 months since last update — extension is effectively abandoned with broad content-script access on all URLs.
  • Privacy policy is Google's generic account policy; not scoped to this extension, admits data collection and 3rd-party sharing.
  • Brand impersonation: name contains 'Zoom' but developer is unaffiliated (gmx.com free-webmail dev, not verified).
  • Content scripts injected into all http/https/file pages with no CSP — full DOM read/write on every site visited.
  • Developer email on gmx.com (free webmail, looks_throwaway flagged); no verified publisher badge.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; 'Zoom' mentioned but confirmed_owner=false, dev is dw-dev@gmx.com.
  • privacy_policy_generic store Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 Privacy (v3.5-D).
  • stale_extension store Last updated April 2023; months_since_update=38. Triggers +10.0 Maintenance and triple-stale fingerprint.
  • content_scripts_broad manifest content_scripts_matches covers http://*/*, https://*/*, file:///*, no CSP present.
  • throwaway_dev_domain api developer_domain_info.looks_throwaway=true for gmx.com; free webmail domain.
  • featured_by_google store is_featured_by_google=true; provides -2.0 Reputation discount (not verified publisher).
  • no_cve_no_bad_hosts crx cve_findings_raw=[], bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — no active threat signals.
  • triple_stale_fingerprint store months>24 + MV3 (no CVEs present, so partial) + no CSP; v2c +2.0 Webstore applied.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles; moderate data exposure.
  • webNavigation medium Observes navigation events across all tabs; page-visit tracking risk.
  • contextMenus low Adds items to right-click menus; low standalone risk.
  • notifications low Can show browser notifications; low risk.
  • storage low Local extension storage; low risk.
  • content_scripts http://*/* high Injects scripts into all HTTP pages; broad read/write access to page content.
  • content_scripts https://*/* high Injects scripts into all HTTPS pages; broad read/write access to page content.
  • content_scripts file:///* medium Injects scripts into local files; can read local filesystem content.

Pillar Scores

Permissions4.50
Reputation7.50
Network0.00
Webstore4.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:18
Listing SHA 74033caefba3…
Force block — not fired
Score recovered no
Elapsed 23.2s