Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

VB Notes - YouTube Notes Pro

begjfebldmhfcbgohdgcpajedndfdnej
Risk Score
4.75
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 3
Rating
Last updated 2025-10-05 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer cipherux@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL times out (ConnectTimeout) — effectively no accessible policy; scored as fetched==false.
  • YouTube brand impersonation in title by unverified gmail developer; confirmed_owner==false.
  • innerHTML DOM-XSS sink in content.js with no CSP present; amplifies XSS risk on YouTube/Vimeo.
  • Description promises recording capability but lacks tabCapture/desktopCapture — permission mismatch.
  • External JS host quilljs.com loaded without CSP; MV3 but no content_security_policy set.

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false (ConnectTimeout); treated as no accessible policy → +10.0 privacy.
  • brand_impersonation_youtube store brand_mention.is_impersonation==true, confirmed_owner==false, developer on gmail.com → +2.0 reputation.
  • free_webmail_developer store Developer email cipherux@gmail.com; not verified publisher, no business domain → +1.5 reputation.
  • dom_xss_sink_no_csp crx dom_sink_innerhtml_userctrl in content.js + csp_present==false → +2.0 code quality (FIX B).
  • description_promise_mismatch store Promises recording but lacks tabCapture/desktopCapture → +2.0 webstore.
  • external_js_host_quilljs crx js_external_hosts includes quilljs.com; no CSP to restrict script loading.
  • maintenance_6_to_12_months store months_since_update==9 → maintenance +3.5.
  • no_cve_findings crx cve_findings_raw empty → CVE pillar 0.0.

Permissions Breakdown

  • identity low OAuth token access; scoped to extension sign-in, low risk without broad host.
  • storage low Local data persistence only; standard low-risk permission.
  • activeTab low Transient access to current tab on user gesture; well-scoped.
  • tabs medium Can read tab URLs and titles across all tabs; moderate metadata exposure.
  • downloads medium Can trigger file downloads; potential for unwanted file writes.
  • https://www.youtube.com/* medium Content script and host access on YouTube; scoped to stated function.
  • https://vimeo.com/* medium Content script and host access on Vimeo; scoped to stated function.
  • https://vbnotes.com/* low Access to own backend domain only; expected for notes sync.

Pillar Scores

Permissions2.30
Reputation6.50
Network2.00
Webstore4.00
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-08 13:48
Listing SHA 47e50bf9900d…
Force block — not fired
Score recovered no
Elapsed