Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Clear Cache Plus

bgdkbjcdecedfoejdfgeafdodjgfohno
Risk Score
4.71
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 17
Rating
Last updated 2025-09-22 (11 months ago)
Manifest version MV3
CSP present ✅ yes
Developer viktornadiezhdin@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's own policy — not scoped to this extension; admits data collection and third-party sharing.
  • CSP sandbox allows unsafe-eval and unsafe-inline plus remote CDN scripts (cdn.paddle.com, cloudapi.stream).
  • browsingData + declarativeNetRequestWithHostAccess are high-capability permissions for a 17-install anonymous developer.
  • Developer is free-webmail (gmail) with no developer name and no verifiable business identity.
  • Small install count with high-tier permissions flags install_perm_anomaly — elevated tail-attack surface.

Evidence

  • Privacy policy is Google's own account policy — scope_extension=false, data_collection=true, third_party_sharing=true api policy URL myaccount.google.com/privacypolicy; 479 KB Google account policy; no extension-specific scope.
  • CSP sandbox allows unsafe-eval, unsafe-inline, and remote CDN script sources manifest sandbox CSP includes cdn.paddle.com, buy.paddle.com, cloudapi.stream with unsafe-eval and unsafe-inline.
  • External JS hosts include payment and cloud streaming endpoints crx api.paddle.com, paddle.net, cloudapi.stream, cognito-identity. — monetization/cloud infra beyond stated function.
  • Developer email is free webmail with no developer name listed store viktornadiezhdin@gmail.com; developer_name empty; no business website verifiable.
  • install_perm_anomaly: small_install_high_perm=true (17 installs, browsingData + declarativeNetRequestWithHostAccess) api Only 17 installs but holds two HIGH-tier permissions — elevated tail-attack-surface risk.
  • verified_publisher=true but free webmail, no dev name, generic Google policy store Verification badge present but does not resolve identity gaps; v3.5 E cap applies for generic policy.
  • No bad_host_hits, no monetization_hits, no affiliate_hits, no CVEs, no code findings api Threat intel and code scan clean; no active exfiltration signals detected.
  • months_since_update=11; maintenance moderate risk store Last updated Sept 2025; 11 months puts it in 6-12mo band (+3.5 maintenance).

Permissions Breakdown

  • browsingData high Can clear cookies, cache, history — broad destructive and data-access capability.
  • declarativeNetRequestWithHostAccess high Allows network request interception/modification with host access scope.
  • activeTab medium Access current tab content on user action; scoped but still meaningful.
  • alarms low Scheduling only; no data access.
  • offscreen low Creates hidden document; low risk without code findings.
  • storage low Local extension storage; standard for settings persistence.

Pillar Scores

Permissions4.50
Reputation5.50
Network5.50
Webstore4.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:07
Listing SHA d0f67567670f…
Force block — not fired
Score recovered no
Elapsed