Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Tab Resize - split screen layouts

bkpenclhmiealbebdopglffmfdiilejc
Risk Score
4.23
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 1,000,000
Rating 4.3
Last updated 2024-06-11 (24 months ago)
Manifest version MV3
CSP present ✅ yes
Developer pdotjs@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension, admits data collection and 3rd-party sharing.
  • Developer uses Gmail address with no verifiable business domain; personal dev, no accountability layer.
  • 24 months since last update at boundary — extension approaching stale threshold for 1M-user install base.
  • Two innerHTML DOM-XSS sinks in layout code; CSP is self-only so mitigated but coding hygiene concern.
  • Google Analytics telemetry present; only telemetry-tier monetization hit, low severity but non-zero data reach.

Evidence

  • privacy_policy_generic store Policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
  • developer_email_free_webmail manifest pdotjs@gmail.com — free webmail, no business domain. Reputation starts at 5.0 +1.5 = 6.5, capped by featured discount.
  • is_featured_by_google store Extension carries Google Featured badge → -2.0 Reputation discount applied.
  • months_since_update_24 store Last updated June 2024; 24 months = boundary of 12-24mo band → Maintenance +6.0.
  • dom_sink_innerhtml_userctrl crx Two files with innerHTML assigned from variable; CSP present (self-only) limits external script injection.
  • google_analytics_telemetry crx www.google-analytics.com in js_external_hosts; monetization_hits tier=telemetry only → +1.0 Webstore.
  • install_count_1M store 1,000,000 installs → Webstore +1.0 (>10K) +1.0 (>100K) +0.5 (>1M) -0.5 (rating>=4.0).
  • cve_findings_empty crx No CVEs found in bundled libraries; CVE pillar = 0.0.

Permissions Breakdown

  • tabs medium Needed for split-screen layout; accesses tab URLs and metadata.
  • system.display low Read display info for layout calculations; no data exfil risk.
  • storage low Stores user layout preferences locally.
  • favicon low Reads tab favicons for UI display only.

Pillar Scores

Permissions1.90
Reputation6.00
Network1.50
Webstore2.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA 45cce043e1b6…
Force block — not fired
Score recovered no
Elapsed 24.6s