Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Web Developer

bfbameneiokkgbdmiekhjnmfkcnldhhm
Risk Score
5.34
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 1,000,000
Rating 4.5
Last updated 2024-06-29 (27 months ago)
Manifest version MV3
CSP present ❌ no
Developer website@chrispederick.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • cookies + scripting + <all_urls> enables full session credential access on every site visited.
  • browsingData and contentSettings grant destructive/override capability across the entire browser.
  • 24 months since last update places extension in stale maintenance band with 1M+ users.
  • No CSP (MV3 default enforced, but 12 external JS hosts contacted including non-dev domains).

Evidence

  • broad_host_access manifest host_permissions=[<all_urls>] + content_scripts on <all_urls>; amplifies cookies/scripting risk.
  • generic_privacy_policy store Policy is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy +10.
  • stale_maintenance store Last updated June 2024; months_since_update=24 → Maintenance +6.0.
  • verified_publisher store verified_publisher=true; chrispederick.com resolves, not throwaway. Discount capped at -1.0 (monetization_hits check: empty, so full -3 applies but v3.5(E) not triggered).
  • external_js_hosts crx 12 external JS hosts including beautifier.io, validator.w3.org, wave.webaim.org — dev-tool references, justify broad network.
  • install_url_hijack crx install_url_hijack=true targeting chrispederick.com/work/web-developer — own domain, not 3rd-party hijack.
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 48 JS files scanned cleanly.
  • no_cve_findings crx cve_findings_raw empty; no vulnerable bundled libraries detected.

Permissions Breakdown

  • browsingData high Can clear browsing history, cookies, cache — destructive and sensitive.
  • contentSettings high Can change per-site content settings (JS, plugins, popups) globally.
  • cookies high Read/write cookies across all sites; session hijack risk when paired with <all_urls>.
  • history medium Full browsing history access; significant privacy exposure.
  • scripting high Programmatic script injection into any page via <all_urls> host permission.
  • storage low Local extension storage only; low standalone risk.
  • tabs medium Access to tab URLs and metadata across all open tabs.
  • <all_urls> (host_permission) high Broad host access amplifies cookies, scripting, and browsingData risks ×1.2.

Pillar Scores

Permissions7.50
Reputation3.50
Network4.50
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sectestoff17515 5.49 Medium review 2026-09-10
sssiedndd078757dp727562726963xsx 5.78 Medium review 2026-09-02
%27fsssiedxa xx psssiedx 5.63 Medium review 2026-08-22
&#x27;fsssiedxa'sssiedx 5.67 Medium review 2026-08-22
&#x27;fsssiedxa$"sssiedx 5.57 Medium review 2026-08-22
&#x22;fsssiedxa$'sssiedx 6.13 High review 2026-08-22
fsssiedxa$"sssiedx 5.99 Medium review 2026-08-22
<fsssiedxa xx psssiedx 5.77 Medium review 2026-08-10
<fsssiedxa'sssiedx 5.79 Medium review 2026-08-10
<fsssiedxa&#x22;sssiedx 5.74 Medium review 2026-08-10
<fsssiedxa$"sssiedx 5.96 Medium review 2026-08-10
<fsssiedxi xx psssiedx 5.76 Medium review 2026-08-10
<fsssiedxi"sssiedx 5.71 Medium review 2026-08-10
<fsssiedxi 5.79 Medium review 2026-08-10
<fsssiedxi$'sssiedx 5.85 Medium review 2026-08-10
fsssiedx<sssiedx 5.76 Medium review 2026-08-10
xx pfsssiedxa sssiedx 5.94 Medium review 2026-08-06
%27fsssiedxa"sssiedx 5.88 Medium review 2026-08-06
'fsssiedxa$'sssiedx 5.58 Medium review 2026-08-06
5.84 Medium review 2026-08-06
&#x27;fsssiedxa sssiedx 5.41 Medium review 2026-08-06
&#x22;fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 5.72 Medium review 2026-08-06
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 5.85 Medium review 2026-08-06
<fsssiedxa$'sssiedx 5.87 Medium review 2026-08-06
fsssiedxa<sssiedx 5.83 Medium review 2026-08-06
v3.6"><script>2zve(9066)</script> 5.87 Medium review 2026-08-05
1}}"}}'}}1%>"%>'%><%={{={@{#{${dfb}}%> 5.71 Medium review 2026-08-05
<%={{={@{#{${dfb}}%> 5.70 Medium review 2026-08-05
v3.6&n917491=v983054 6.05 High review 2026-08-05
dfb__${98991*97996}__::.x 5.71 Medium review 2026-08-04
v3.6&n926982=v950383 5.89 Medium review 2026-08-04
fsssiedxa sssiedx 5.73 Medium review 2026-08-03
fsssiedxa'sssiedx 5.28 Medium review 2026-08-03
fsssiedxa$'sssiedx 5.69 Medium review 2026-08-03
sssieddrubricxsx 5.71 Medium review 2026-08-03
%76%33%2E%36%39%34%32%35%22%28%29%3B%7D%5D%39%32%30%37 5.78 Medium review 2026-07-29
%76%33%2E%36%22%6F%6E%6D%6F%75%73%65%6F%76%65%72%3D%36%73%71%49%28%39%34%36%37%34%29%22 5.78 Medium review 2026-07-29
dfb{{98991*97996}}xca 5.87 Medium review 2026-07-29
bfg4051<s1﹥s2ʺs3ʹhjl4051 5.93 Medium review 2026-07-29
<th:t="${dfb}#foreach 5.88 Medium review 2026-07-29
v3.69112594 6.01 High review 2026-07-29
v3.6&n904945=v908954 5.69 Medium review 2026-07-29
v3.6 5.34 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA d106db64ed67…
Force block — not fired
Score recovered no
Elapsed 24.3s