Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Amazon Wish List Total

boekbkconiendicldakeboooeilaldmh
Risk Score
5.07
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Shopping
Installs 30,000
Rating 4.0
Last updated 2024-05-16 (25 months ago)
Manifest version MV3
CSP present ❌ no
Developer jasontbradshaw+amazon-wish-list-total@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (scope_extension=false, admits data_collection+third_party_sharing) — worst-case +10.0 privacy score.
  • Extension stale 25 months; v3.2 triple-stale fingerprint (>24mo + MV3 + no CSP) raises maintenance concern.
  • Brand impersonation flag: 'amazon' in name, confirmed_owner=false, gmail dev — not verified publisher or featured by publisher.
  • No CSP present (MV3 so no +2.0 network penalty, but dom-sink risk unmitigated if code changes).
  • Free-webmail developer email with no business domain raises attribution accountability risk.

Evidence

  • privacy_policy_generic store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 rule D).
  • brand_impersonation store brand_mention.is_impersonation=true, confirmed_owner=false, not verified_publisher → +2.0 reputation.
  • maintenance_stale store months_since_update=25 (24-36mo band) → +8.5 maintenance pillar.
  • no_csp manifest content_security_policy=null; MV3 so no +2.0 network penalty, but no hardening present.
  • free_webmail_dev store Developer email is gmail.com; no business website; +1.5 reputation base.
  • is_featured_by_google store is_featured_by_google=true → -2.0 reputation discount applied.
  • clean_code_scan crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[] → code quality 0.0.
  • no_cve_findings crx cve_findings_raw=[] → CVE pillar 0.0.

Permissions Breakdown

  • content_scripts (*://*.amazon.*/gp/aw/ls/*, /gp/registry/*, /hz/wishlist/*) medium Injects script on Amazon wish-list paths across 15+ regional domains; scoped to stated function.

Pillar Scores

Permissions1.00
Reputation7.00
Network2.00
Webstore2.00
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:21
Listing SHA 072d06280ed7…
Force block — not fired
Score recovered no
Elapsed 22.2s