Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Spotify Playback Speed

bgehnoihoklmofgehcefiaicdcdgppck
Risk Score
4.78
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 60,000
Rating 4.7
Last updated 2025-03-05 (15 months ago)
Manifest version MV3
CSP present ❌ no
Developer chromedev@rnikko.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; admits data collection & 3rd-party sharing.
  • Brand impersonation flag: extension uses 'Spotify' brand name without confirmed ownership.
  • No CSP + innerHTML sink creates DOM-XSS exposure on every Spotify page load.
  • Dynamic script injection (script_src_dynamic) from extension package bypasses content review.
  • 15-month stale update with featured badge; v3.5 invariant 0c caps verified/featured discount.

Evidence

  • privacy_policy_generic_google store PP URL is myaccount.google.com — Google's own policy, not scoped to this extension. scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • brand_impersonation store brand_mention.is_impersonation=true for 'spotify'; confirmed_owner=false; not verified publisher → +2.0 reputation.
  • no_csp_mv3 manifest content_security_policy is null; no CSP present. Amplifies DOM-XSS risk from innerHTML sink.
  • code_script_src_dynamic crx content-script.js dynamically creates <script src=chrome.runtime.getURL('script.js')> — self-hosted but flagged pattern.
  • code_dom_sink_innerhtml crx script.js assigns user-controlled variable to innerHTML with no CSP and no CVEs; triggers +2.0 FIX B.
  • maintenance_stale store Last updated March 2025; 15 months since update → +6.0 maintenance pillar.
  • featured_badge store is_featured_by_google=true; provides -2.0 reputation discount, but invariant 0c applies (stale >18mo cap: 15mo — below 18 threshold, full discount applies).
  • installs_60k store 60,000 installs; >10,000 threshold adds +1.0 webstore blast radius.

Permissions Breakdown

  • content_scripts: https://open.spotify.com/* medium Injects JS into Spotify web player only; narrowly scoped but still grants DOM access.

Pillar Scores

Permissions1.00
Reputation6.50
Network2.00
Webstore3.50
Maintenance6.00
Privacy10.00
Code Quality5.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:19
Listing SHA 92325ea7ec19…
Force block — not fired
Score recovered no
Elapsed 23.6s