Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Launchpad Hero

bmkccjgdfgjhfjbghpapedknkdokebfi
Risk Score
3.36
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 50,000
Rating 4.8
Last updated 2025-01-13 (20 months ago)
Manifest version MV3
CSP present ❌ no
Developer launchpadhero@outlook.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Developer uses free webmail (outlook.com) with no verified publisher badge — low accountability.
  • Extension is 20 months stale (High maintenance risk) with 50K installs still active.
  • DOM-XSS sink (innerHTML on user-controlled variable in popup.js) with no CSP to mitigate.
  • Privacy policy discloses data collection and third-party sharing but extension has no declared permissions — scope mismatch warrants scrutiny.
  • Manifest uses localized placeholders (__MSG_appName__) making store-listing verification harder.

Evidence

  • developer_email_free_webmail store Developer email launchpadhero@outlook.com is a free webmail address; no verified publisher badge.
  • months_since_update_20 store Last updated January 13, 2025; 20 months stale — scores in High maintenance band (6-12mo +3.5, 12-24mo +6.0 applied at 20mo).
  • dom_sink_innerhtml_userctrl crx popup.js assigns user-controlled variable to innerHTML with no CSP; DOM-XSS risk.
  • no_permissions_declared manifest permissions[], host_permissions[], and content_scripts_matches[] all empty — zero declared permissions.
  • js_external_hosts_yahoo crx 12 Yahoo subdomains in js_external_hosts; extension contacts external hosts despite empty permissions — unusual.
  • privacy_policy_data_collection_third_party api Privacy policy discloses data collection and third-party sharing; retention documented.
  • csp_absent manifest content_security_policy is null; no CSP mitigates the innerHTML XSS sink.
  • manifest_localized_placeholders manifest manifest_name and manifest_description use __MSG__ placeholders, obscuring store listing review.

Pillar Scores

Permissions0.00
Reputation6.50
Network2.00
Webstore1.00
Maintenance6.00
Privacy1.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 15:40
Listing SHA f4791588db51…
Force block — not fired
Score recovered no
Elapsed