Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

BookMyShow Auto-Book

cahbnklfddaodggaamglmfdnogpgmnla
Risk Score
3.26
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Productivity
Installs 61
Rating
Last updated 2026-08-24 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer nareshipme@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is a generic Privyr-generated template not scoped to this extension; admits data collection and third-party sharing.
  • Developer uses free Gmail account with no business identity or verified publisher status.
  • No developer name provided; accountability is minimal.
  • Very low install count (61) with zero ratings — unvetted by community.
  • Privacy policy hosted on third-party S3 bucket (privyr.com), not on a dev-controlled domain.

Evidence

  • privacy_policy_generic api Policy fetched from s3.privyr.com (auto-generated template); scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer_identity store Developer email is nareshipme@gmail.com (free webmail). No developer_name provided. No verified publisher.
  • permissions_scoped manifest Permissions limited to storage, activeTab, notifications, tts. Host access scoped to in.bookmyshow.com only.
  • no_bad_hosts api threat_intel bad_host_hits, monetization_hits, and affiliate_hits are all empty.
  • no_code_findings crx code_findings_raw empty; obfuscation_score=0.0; 3 JS files scanned cleanly.
  • no_cves crx cve_findings_raw empty; no bundled vulnerable libraries detected.
  • low_install_count store Only 61 installs; zero ratings; extension is effectively unvetted.
  • host_geo_single api JS external hosts resolve to 1 country (CA); no geo-diversity concern.

Permissions Breakdown

  • storage low Stores local extension state; no cross-origin risk.
  • activeTab low Grants access only to current tab on user action; transient scope.
  • notifications low Displays system notifications; no data exfil risk on its own.
  • tts low Text-to-speech output only; no read access to page content.
  • https://in.bookmyshow.com/* medium Scoped host access to a single known domain matching stated function.

Pillar Scores

Permissions1.90
Reputation6.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-09-01 12:36
Listing SHA 544ba90035cb…
Force block — not fired
Score recovered no
Elapsed