Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Twitter Print Styles

bepilablapiogeghmjiopiaoikgdcgjo
Risk Score
3.55
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 3,000
Rating 3.5
Last updated 2025-03-05 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer me@tannerhodges.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection and 3rd-party sharing (v3.5 D: +10.0 privacy).
  • Extension is 15 months stale with no CSP declared (MV3 default covers eval but policy gap remains).
  • Brand mention of 'twitter' flagged as impersonation by classifier; developer is unverified individual with no listed name.
  • Developer email domain tannerhodges.com resolves but developer_name is empty — reduced accountability.
  • Rating 3.5 with small install base; no review red flags but low trust signal.

Evidence

  • privacy_policy_generic store Privacy URL points to myaccount.google.com — fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true for 'twitter'; not verified publisher per brand rule → +2.0 reputation. BUT is_featured_by_google=true applies +1.0 variant.
  • verified_publisher_featured store verified_publisher=true AND is_featured_by_google=true; discounts applied to reputation. No HIGH-capability gate triggered.
  • maintenance_stale store months_since_update=15; falls in 12-24mo band → +6.0 maintenance.
  • no_csp manifest content_security_policy=null; MV3 so no +2.0 network penalty, but dom_sink risk context noted.
  • code_clean crx code_findings_raw=[], obfuscation_score=0.0, no CVEs, no external JS host exfil detected.
  • host_permissions_scoped manifest host_permissions limited to twitter.com and x.com; matches stated function; justified-broad discount applied.
  • operator_cluster_clean api sibling_count=0, no bad_host_hits, no monetization_hits, no affiliate_hits.

Permissions Breakdown

  • host_permission: https://twitter.com/* medium Content script access scoped to twitter.com; matches stated function of print styles.
  • host_permission: https://x.com/* medium Content script access scoped to x.com (Twitter rebrand); matches stated function.

Pillar Scores

Permissions1.50
Reputation4.50
Network0.00
Webstore1.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA 0f5f96e20a8d…
Force block — not fired
Score recovered no
Elapsed 20.8s