Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Sticky Password manager & safe

bnfdmghkeppfadphbnkjcicejfepnbfe
Risk Score
4.77
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Security
Installs 90,000
Rating 3.9
Last updated 2026-01-30 (5 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@stickypassword.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetch failed — privacy posture completely unknown; 10.0 privacy pillar score.
  • nativeMessaging with unrecognized publisher bridges extension to OS-level companion app (+3.0 perm).
  • Broad content scripts on all HTTP/HTTPS pages give full DOM access on every site visited.
  • innerHTML DOM-XSS sink in spUninstall.js; CSP present but user-controlled value assignment is risky.
  • No developer name listed; rating 3.9 without count context reduces reputation confidence.

Evidence

  • nativeMessaging_unrecognized_publisher crx native_messaging_check.publisher_recognized=false; companion app can execute arbitrary OS code.
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError); policy content unverifiable → +10.0.
  • broad_content_scripts manifest content_scripts_matches includes http://*/* and https://*/* — runs on every HTTP/HTTPS page.
  • dom_xss_sink crx spUninstall.js: innerHTML assigned from variable AValue — DOM-XSS risk, CSP present mitigates somewhat.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity for attribution.
  • no_bad_hosts_no_affiliates api threat_intel: bad_host_hits=[], affiliate_hits=[], monetization_hits=[] — clean threat intel.
  • csp_present_mv3 manifest script-src 'self'; object-src 'self' — strict CSP, MV3, no unsafe-eval/inline.
  • js_external_hosts_reference_only crx 12 external hosts in JS all appear to be documentation/spec references (github, MDN, W3C, etc.).

Permissions Breakdown

  • privacy high Can read/write browser privacy settings — broad control over user privacy configuration.
  • tabs medium Access to tab URLs and metadata — needed for autofill but enables browsing history inference.
  • storage low Local credential/settings persistence — expected for a password manager.
  • notifications low Can push desktop notifications — low standalone risk.
  • nativeMessaging high Bridges to companion desktop app; publisher not recognized — high privilege escalation path.
  • content_scripts http://*/* https://*/* high Broad content script injection on all HTTP/HTTPS pages — full DOM read/write on every site.

Pillar Scores

Permissions7.00
Reputation5.50
Network0.00
Webstore1.00
Maintenance1.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA c72b6033a43b…
Force block — not fired
Score recovered no
Elapsed 25.1s