Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Clipboard Manager

blicpdhhajlodleohohaeommdmpjfoab
Risk Score
4.72
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 5,000
Rating 2.8
Last updated 2025-08-04 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer mujo.hydrov@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is generic Google account policy — not scoped to this extension, covers data collection and third-party sharing.
  • Content script injected on *://* gives extension access to every page the user visits despite minimal declared permissions.
  • Install and uninstall URL hijack flags set; install_url_target and uninstall_url_target are null so destination is unverifiable.
  • Developer uses free Gmail account with no business domain; operator cluster shows 1 sibling extension under same fingerprint.
  • Rating of 2.8 is low, suggesting user dissatisfaction; no review red-flags found but small install base limits signal quality.

Evidence

  • content_scripts_broad manifest content_scripts_matches: ['*://*/*'] — runs on every HTTP/HTTPS page despite only storage/contextMenus/notifications declared.
  • privacy_policy_generic store Policy URL is Google account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • install_uninstall_hijack crx install_url_hijack=true and uninstall_url_hijack=true; targets are null so destination cannot be assessed.
  • free_webmail_developer store Developer email mujo.hydrov@gmail.com; no business domain; domain_age_ct not queried (free webmail).
  • operator_cluster api sibling_count=1 (bcieicfnbnmlffkgbiemoofinidpgloa) under same dev-email fingerprint → +2.5 webstore.
  • low_rating store Rating 2.8; rating_count not available; below 3.0 threshold but count unknown.
  • is_featured_by_google store Extension carries 'Featured' badge; applied -2.0 to reputation but does not offset policy/hijack risks.
  • no_csp manifest content_security_policy is null (MV3 so no +2.0 network penalty, but no CSP amplifier applied — no CVEs to trigger it).

Permissions Breakdown

  • storage low Stores clipboard history locally; expected for this category.
  • contextMenus low Adds right-click menu entries; matches stated functionality.
  • notifications low Sends browser notifications; low standalone risk.
  • content_scripts *://*/* high Injects scripts into every page; broad reach despite low declared permissions.

Pillar Scores

Permissions2.00
Reputation7.00
Network0.00
Webstore6.50
Maintenance3.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Operator Siblings (1)

Other extensions sharing this developer's compound fingerprint:

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA cbf40aa7f8d4…
Force block — not fired
Score recovered no
Elapsed 23.9s