Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Super Focus Tabs

blecebkjfbkpannnmajllilknpccheak
Risk Score
6.16
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Productivity
Installs 1,000
Rating 3.9
Last updated 2023-06-09 (36 months ago)
Manifest version MV3
CSP present ✅ yes
Developer nghiai3e@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — not scoped to this extension; third-party sharing admitted without extension context.
  • Extension stale for 36 months with <all_urls> content scripts and history/bookmarks access — high abandonment/takeover risk.
  • Developer is free-webmail gmail user with no business identity; no verified publisher badge.
  • install_url_hijack flag set — onInstalled may open an untracked third-party URL.
  • CSP sandbox profile allows unsafe-eval and unsafe-inline, weakening script isolation.

Evidence

  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension; scope_extension=false, third_party_sharing=true.
  • stale_extension store Last updated June 2023; months_since_update=36 — at maintenance boundary, high abandonment risk.
  • free_webmail_developer store developer_email=nghiai3e@gmail.com; no business domain, no verified publisher, no featured badge that overrides reputation floor.
  • install_url_hijack crx install_url_hijack=true; target null — onInstalled opens external URL, possible traffic monetization.
  • dom_xss_sink crx scripts/Interface.min.js: innerHTML assigned from tab-count variable; DOM-XSS risk though CSP extension_pages is strict.
  • sandbox_csp_unsafe crx Sandbox CSP allows unsafe-eval and unsafe-inline on script-src, reducing XSS protection in sandboxed context.
  • host_permission_all_urls manifest <all_urls> in host_permissions + content_scripts_matches; combined with history and bookmarks is high-reach capability.
  • telemetry_only_network crx js_external_hosts: google.com, www.google-analytics.com only; single US geo; no bad-host hits.

Permissions Breakdown

  • tabs medium Access to tab URLs and titles across all open tabs.
  • storage low Standard local data persistence.
  • alarms low Scheduled background tasks; minimal risk.
  • contextMenus low Adds right-click menu entries; low risk.
  • history medium Can read and modify full browsing history.
  • bookmarks medium Can read and modify all bookmarks.
  • unlimitedStorage low Allows large local storage; no direct privacy risk.
  • favicon low Access to tab favicons; minimal risk.
  • system.display low Read display configuration; minimal risk.
  • <all_urls> (host) high Content scripts run on every page; broad reach combined with history/bookmarks.

Pillar Scores

Permissions6.00
Reputation7.00
Network2.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA 73fe7e628145…
Force block — not fired
Score recovered no
Elapsed 25.7s