Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Webshare Proxy Extension

bdokeillmfmaogjpficejjcjekcflkdh
Risk Score
4.67
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category VPN
Installs 80,000
Rating 4.7
Last updated 2026-04-28 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@webshare.io
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • proxy+webRequest+<all_urls>+cookies: full traffic interception and credential theft capability on compromise.
  • Privacy policy fetched but scope_extension=false and admits data collection + third-party sharing — worst-case privacy posture.
  • No CSP on MV3 extension with innerHTML DOM-XSS sink in popup JS.
  • No developer name listed; webshare.io domain resolves and is not throwaway but identity accountability is reduced.
  • posthog-js analytics bundled — user behaviour telemetry without extension-scoped retention disclosure.

Evidence

  • high_permission_combo manifest proxy+webRequest+cookies+privacy+<all_urls> — maximum traffic interception surface for a proxy tool.
  • privacy_policy_generic crx Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true, retention=false → +10.0 privacy.
  • no_csp manifest content_security_policy is null on MV3 extension with innerHTML sink in popup.
  • dom_xss_sink crx dom_sink_innerhtml_userctrl in popup-DBWXjTrF.js; no CSP present → elevated to +2.0 code quality.
  • featured_by_google store is_featured_by_google=true — partial trust signal, but not verified publisher.
  • no_developer_name store developer_name is empty string; email domain webshare.io resolves and is not throwaway.
  • posthog_analytics crx posthog-js detected in sourcemaps; analytics telemetry without extension-scoped retention disclosure.
  • no_bad_hosts api threat_intel bad_host_hits, monetization_hits, affiliate_hits all empty; developer domain resolves.

Permissions Breakdown

  • proxy high Can redirect all browser traffic through attacker-controlled servers if compromised.
  • webRequest high Intercept and inspect all HTTP requests across all URLs.
  • privacy high Can alter Chrome privacy settings including proxy, tracking protection, etc.
  • cookies high Access to cookies on all URLs combined with <all_urls> host access is critical.
  • <all_urls> high Full host access to every site the user visits.
  • identity low OAuth identity access; low risk without explicit scopes.
  • storage low Local extension storage; low standalone risk.
  • webRequestAuthProvider high Can inject proxy credentials into auth challenges — needed for proxy auth but sensitive.

Pillar Scores

Permissions7.00
Reputation4.50
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA b6f4484a058d…
Force block — not fired
Score recovered no
Elapsed 26.0s