Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Advanced Image Search

cahpmepdjiejandeladmhfpapeagobnp
Risk Score
5.35
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 10,000
Rating 3.7
Last updated 2023-10-05 (32 months ago)
Manifest version MV3
CSP present ❌ no
Developer polywockhelp@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — scoped to Google, not this extension; admits data collection and 3rd-party sharing.
  • Extension is 32 months stale (zombie-tier), raising supply-chain takeover risk.
  • Developer uses free Gmail address with brand_mention.is_impersonation=true (mentions Google, not verified owner).
  • is_featured_by_google=true partially offsets reputation, but free-webmail + impersonation floor keeps reputation high.
  • No CSP on MV3 (no penalty per v2b), but combined stale + impersonation + bad privacy warrants review.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[google]; developer_domain=gmail.com; confirmed_owner=false.
  • free_webmail_dev manifest developer_email=polywockhelp@gmail.com; no business website; gmail developer domain.
  • generic_privacy_policy api Policy is Google's account policy (460KB); scope_extension=false, data_collection=true, third_party_sharing=true.
  • zombie_stale store months_since_update=32; last update October 2023; >24 months stale with 10K installs.
  • featured_by_google store is_featured_by_google=true; applies -2.0 reputation discount but impersonation+gmail floor reputation at 7.5.
  • low_permissions manifest Only 'storage' declared; no host_permissions, no content_scripts — very narrow capability.
  • no_cve_no_bad_hosts crx cve_findings_raw=[], bad_host_hits=[], monetization_hits=[], code_findings_raw=[] — clean scan.
  • external_hosts crx js_external_hosts=[chrome.google.com, github.com, google.com]; all Google/GitHub; no ad-tech.

Permissions Breakdown

  • storage low Stores extension settings locally; no cross-site or data-exfil risk on its own.

Pillar Scores

Permissions0.30
Reputation7.50
Network0.00
Webstore4.50
Maintenance8.50
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA b4f3f8387eb4…
Force block — not fired
Score recovered no
Elapsed 19.9s