Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

X (Twitter) Mass Unfollow

bidolfkgmbnlnijabkjafdajjpocfhol
Risk Score
5.27
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 30,000
Rating 4.2
Last updated 2025-05-20 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer olushilukmon03@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (scope_extension=false, admits data collection and third-party sharing) — scores maximum privacy risk.
  • Brand impersonation: 'twitter' mentioned in name/description by unverified gmail developer who does not own the brand.
  • Developer uses free webmail (gmail) with no business domain or verified publisher status.
  • Install URL hijack opens options.html on install — minor UX manipulation but flags low-quality governance.
  • Extension last updated 13 months ago with no changelog; moderate staleness for a social-platform automation tool.

Evidence

  • generic_privacy_policy store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true — worst-case privacy score.
  • brand_impersonation store brand_mention.is_impersonation=true for 'twitter'; developer is unverified gmail user, not Twitter/X Corp.
  • free_webmail_developer store Developer email olushilukmon03@gmail.com; no business domain, no verified publisher badge.
  • install_url_hijack manifest install_url_hijack=true targeting options.html on install — low-severity governance flag.
  • content_script_scope manifest content_scripts_matches restricted to https://*.x.com/*/following — narrow, fits stated purpose.
  • maintenance_staleness store Last updated May 2025, months_since_update=13; falls in 12-24mo bracket (+6.0 maintenance).
  • no_csp manifest content_security_policy=null; MV3 default applies, no amplifier triggered (no CVEs, no high-risk code findings).
  • clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, no external JS hosts beyond github.com.

Permissions Breakdown

  • storage low Stores user preferences locally; minimal risk.
  • declarativeContent low Controls when extension activates; no data access.
  • scripting medium Can inject scripts into active tab; scoped to x.com/following via content_scripts.
  • activeTab low Access only to user-activated tab; limited scope.

Pillar Scores

Permissions2.30
Reputation7.50
Network0.00
Webstore5.50
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA e37233b1985c…
Force block — not fired
Score recovered no
Elapsed 22.5s