Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TuneEase

bhdjjppbnlpjpeicimhemencfgjeldoa
Risk Score
4.31
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 30,000
Rating 4.5
Last updated 2025-09-21 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer dzungnguyen179@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: Spotify brand mentioned, developer not confirmed owner, free-webmail identity only.
  • Install URL hijack: onInstalled opens /setting.html; uninstall URL hijack also flagged.
  • Privacy policy fetched but scope_extension==false and data_collection==false; policy not scoped to this extension.
  • Free-webmail developer (gmail.com) with no verified business domain raises accountability gap.
  • Contacts 7 external hosts including vercel.app backend and twitter.com with no CSP (MV3 mitigates but network surface broad).

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true, Spotify mentioned, confirmed_owner=false, developer domain is gmail.com.
  • install_url_hijack crx install_url_hijack=true targeting /setting.html; uninstall_url_hijack=true.
  • free_webmail_developer store Developer email dzungnguyen179@gmail.com; no verified publisher badge.
  • privacy_policy_not_scoped api Policy fetched but scope_extension=false, data_collection=false; generic policy not scoped to extension.
  • external_hosts_breadth crx 7 external hosts: accounts.spotify.com, api.spotify.com, open.spotify.com, spotify-notification-api.vercel.app, twitter.com, www.tunease.com, localhost.
  • no_csp manifest content_security_policy=null; MV3 provides defaults but no explicit CSP strengthening.
  • cve_findings crx cve_findings_raw empty; no known CVEs detected.
  • operator_cluster api sibling_count=0; no sibling extensions under same fingerprint.

Permissions Breakdown

  • contextMenus low Adds right-click menu items; minimal data access.
  • declarativeContent low Page state inspection for UI triggers; no data exfiltration.
  • storage low Local key-value storage only; standard extension use.
  • host: http://localhost/* low Localhost dev/API access; limited real-world exposure.
  • host: https://www.tunease.com/* low Scoped to dev-owned domain; matches stated function.

Pillar Scores

Permissions0.90
Reputation7.50
Network1.50
Webstore7.50
Maintenance1.50
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA e9df57232965…
Force block — not fired
Score recovered no
Elapsed 20.3s