Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

StackOverflow Answer

bmlkdgmiaemiaopodggkhfblhmefimoi
Risk Score
5.54
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 131
Rating 5.0
Last updated 2022-12-21 (42 months ago)
Manifest version MV3
CSP present ❌ no
Developer renouxpro@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension (generic GitHub policy) — scores max privacy risk.
  • Extension is 42 months stale (>36mo) — abandoned, no security updates, zombie risk.
  • Brand impersonation: mentions 'stackoverflow' and 'google' without verified ownership; free-webmail developer.
  • Broad content_scripts on all URLs (http://*/* https://*/*) despite only needing StackOverflow/Google — high reach with no CSP.
  • No CSP present on MV3 extension contacting external hosts (api.stackexchange.com, cdn.jsdelivr.net).

Evidence

  • privacy_policy_generic_admits_sharing store Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true — generic non-scoped policy admitting data sharing.
  • stale_42_months store Last updated December 2022; 42 months since update — maintenance pillar maxed.
  • brand_impersonation store brand_mention.is_impersonation=true; brands: google, stackoverflow; developer_domain=gmail.com, not verified.
  • free_webmail_developer store Developer email renouxpro@gmail.com — free webmail, no verified business domain.
  • broad_content_scripts manifest content_scripts_matches: http://*/* and https://*/* — runs on all sites despite narrow stated purpose.
  • no_csp_external_hosts crx csp_present=false; external hosts: api.stackexchange.com, cdn.jsdelivr.net, www.apache.org.
  • is_featured_by_google store is_featured_by_google=true — partial trust signal, offsets reputation slightly.
  • no_bad_hosts_no_cves crx bad_host_hits empty, cve_findings_raw empty, code_findings_raw empty, obfuscation_score=0.0.

Permissions Breakdown

  • storage low Stores local extension data only; no cross-site risk.
  • content_scripts http://*/* https://*/* high Broad content script injection on all sites elevates reach significantly.

Pillar Scores

Permissions2.30
Reputation7.50
Network2.00
Webstore2.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA d10fbb9f9a66…
Force block — not fired
Score recovered no
Elapsed 20.0s