Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Screen GIF Maker: Google Animation Creator

bkgdbkfbbpagdomghecnaeljhdfiemeb
Risk Score
6.41
Risk Level: High
Recommendation: 🚫 BLOCK
Category Screenshot
Installs 139
Rating 2.0
Last updated 2024-04-16 (26 months ago)
Manifest version MV3
CSP present ❌ no
Developer extensionseventy@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Brand impersonation: 'Google' in title by unverified gmail developer with no Google affiliation.
  • Privacy policy points to Google's own policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Content script on <all_urls> with no CSP; three innerHTML DOM-XSS sinks across content/options/popup scripts.
  • Extension is 26 months stale (zombie), low installs, rating 2/5 — abandoned with unresolved risk surface.
  • Install-URL hijack detected; onInstalled opens third-party URL of unknown destination.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; 'Google' in title; developer_email=gmail.com; confirmed_owner=false.
  • generic_privacy_policy store Privacy URL is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0.
  • content_scripts_all_urls_no_csp manifest content_scripts_matches=[<all_urls>], csp_present=false; DOM-XSS sinks escalate to +2.0 each (FIX B).
  • install_url_hijack crx install_url_hijack=true, target=null; onInstalled opens unknown third-party URL (+2.0 Webstore).
  • stale_extension store months_since_update=26; 24-36mo band → Maintenance +6.0.
  • free_webmail_developer store developer_email=extensionseventy@gmail.com; numbered alias + no business domain → Reputation floor.
  • numbered_alias_email store Email 'extensionseventy@gmail.com' matches numbered/word-alias pattern → Webstore +3.0.
  • low_rating store Rating=2.0; install_count=139; low user trust signal.

Permissions Breakdown

  • activeTab low Scoped to user-invoked tab; low blast radius on its own.
  • tabCapture medium Captures tab video/audio stream; core for GIF recording but powerful.
  • storage low Local data persistence only.
  • tabs medium Accesses tab URLs and metadata across all open tabs.
  • notifications low Desktop notification display; low standalone risk.
  • content_scripts:<all_urls> high Content script injected on every site; broad DOM access combined with innerHTML sinks.

Pillar Scores

Permissions5.00
Reputation8.50
Network2.00
Webstore6.50
Maintenance6.00
Privacy10.00
Code Quality4.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:20
Listing SHA d460c7397be9…
Force block — not fired
Score recovered no
Elapsed 28.1s