Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Time for Price – See How Long You’d Work for It

bfkgpokiagcanmjfaahdenfngaacogce
Risk Score
3.27
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category PriceTracker
Installs 70
Rating 5.0
Last updated 2026-01-07 (7 months ago)
Manifest version MV3
CSP present ❌ no
Developer timeforpriceapp@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is 207 chars, not scoped to extension, silent on third-party sharing — effectively inadequate.
  • Developer uses free Gmail address with no verified business identity; developer_name is empty.
  • Verified publisher badge present but Gmail dev email weakens identity assurance.
  • Extension is 7 months old with only 70 installs; low adoption limits trust signal.
  • No CSP declared (MV3 mitigates somewhat, but policy gap remains).

Evidence

  • permissions_narrow manifest Only activeTab, scripting, storage; host access limited to 3 Amazon TLDs — minimal attack surface.
  • verified_publisher store Verified publisher badge present; partially offsets Gmail identity concern.
  • dev_gmail store Developer email timeforpriceapp@gmail.com is free webmail; developer_name is empty.
  • privacy_policy_inadequate api Policy fetched (207 chars): scope_extension=false, data_collection=false, third_party_silence=true — stub policy.
  • no_cve crx cve_findings_raw empty; no bundled vulnerable libraries detected.
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 3 JS files scanned cleanly.
  • no_external_hosts crx js_external_hosts=[]; no outbound third-party network calls detected.
  • low_installs store Only 70 installs; minimal blast radius but very low adoption trust signal.

Permissions Breakdown

  • activeTab low Access only to currently active tab on user gesture; no persistent host access.
  • scripting medium Allows injecting scripts; scoped to Amazon domains only via host_permissions.
  • storage low Local data persistence; no cross-origin exposure.
  • host: amazon.com low Narrowly scoped to Amazon checkout pages; matches stated price-tracking function.
  • host: amazon.co.uk low Narrowly scoped UK Amazon; matches stated function.
  • host: amazon.ca low Narrowly scoped Canada Amazon; matches stated function.

Pillar Scores

Permissions1.60
Reputation5.50
Network0.00
Webstore0.00
Maintenance3.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:35
Listing SHA 6fbd13fa3fb5…
Force block — not fired
Score recovered no
Elapsed