Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Trocker

bjojfeillmmoeadgobbcknkgdkngbcdb
Risk Score
4.52
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PrivacyTool
Installs 10,000
Rating 4.5
Last updated
Manifest version MV3
CSP present ❌ no
Developer trockerapp@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope data handling to this extension at all.
  • Developer is a free-webmail identity (gmail.com) with no verified developer name or business domain.
  • declarativeNetRequestWithHostAccess + <all_urls> gives broad network interception capability across all sites.
  • No CSP defined (MV3 default applies but no explicit policy); innerHTML DOM-XSS sink in options.js.
  • last_updated is missing — maintenance posture cannot be assessed; defaults to stale penalty.

Evidence

  • privacy_policy_generic api Policy URL is Google account-level policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10.0 privacy (v3.5 D).
  • free_webmail_developer store developer_email=trockerapp@gmail.com, no developer_name, no business domain — reputation floor applied.
  • verified_publisher_featured store verified_publisher=true and is_featured_by_google=true; reputation discounts applied but capped under v3.5 E conditions.
  • host_permissions_broad manifest <all_urls> paired with declarativeNetRequestWithHostAccess; justified-broad discount applied for PrivacyTool category.
  • dom_xss_sink crx options.js: innerHTML set from variable allOpenTrackerBlocks without sanitisation. No CSP → +2.0 code quality (FIX B).
  • install_url_hijack crx install_url_hijack=true but install_url_target=null; onInstalled opens URL, target unresolvable — +2.0 webstore.
  • maintenance_unknown store last_updated empty, months_since_update=null; treated conservatively as 6-12mo stale (+3.5 maintenance).
  • js_external_hosts crx 12 external hosts in JS including trk.klclick1.com and t.yesware.com (tracking domains); >3 distinct domains +1.5 network.

Permissions Breakdown

  • declarativeNetRequest medium Can block/redirect network requests; core to tracker-blocking function.
  • declarativeNetRequestFeedback medium Reads which rules matched which requests; mild info exposure.
  • declarativeNetRequestWithHostAccess high Enables host-level net request interception across all URLs — HIGH capability.
  • storage low Local extension storage only; low standalone risk.
  • offscreen low Creates hidden offscreen document; minor capability expansion.
  • <all_urls> (host) high Broad host access required for declarativeNetRequestWithHostAccess.
  • *://*.google.com/* (host) medium Scoped to Google domains; content scripts active on mail.google.com.
  • *://*.live.com/* (host) medium Scoped to Microsoft Live/Outlook mail domains.
  • *://*.googleusercontent.com/* (host) low Google user content CDN; limited attack surface.

Pillar Scores

Permissions4.50
Reputation5.00
Network2.00
Webstore2.50
Maintenance5.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA 700cc4a05460…
Force block — not fired
Score recovered no
Elapsed 29.2s