Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

AT Price Tracker (Working August 2026)

cbecfdegmcppmbpbffdpagongfpbohmd
Risk Score
4.31
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category PriceTracker
Installs
Rating
Last updated
Manifest version MV3
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic account policy — does not scope to this extension at all (D rule: fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0).
  • Uninstall URL hijack flag set; uninstall redirect target not captured but signal indicates external redirect attempt.
  • No developer name, email, or verified publisher; anonymous extension with no accountability.
  • Content script injected into third-party domain at.liprock.com with no clear stated purpose — unknown backend.
  • identity.email permission collects Google account email, enabling persistent user identification with no scoped disclosure.

Evidence

  • privacy_policy_generic store Privacy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → privacy pillar +10.0.
  • uninstall_url_hijack crx uninstall_url_hijack=true in manifest; target null but flag indicates external redirect on uninstall.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens onboarding.html (internal page, lower risk).
  • anonymous_developer store developer_name, developer_email all empty; no verified_publisher; reputation floor applies.
  • third_party_content_script manifest Content script on https://at.liprock.com/* — unknown third-party domain not explained by stated function.
  • identity_email_permission manifest identity.email grants read access to user's Google account email address.
  • no_csp crx csp_present=false on MV3; MV3 has strict default so no v2 penalty applied.
  • maintenance_unknown api months_since_update=null; last_updated missing; maintenance pillar scored 0 (no penalty, no data).

Permissions Breakdown

  • identity low OAuth identity access; no scopes declared, limited impact alone.
  • identity.email medium Reads user's Google email address; enables user tracking/profiling.
  • storage low Local extension storage; standard for preference/cache persistence.
  • content_scripts: *://*.autotrader.co.uk/* medium Script injected into all autotrader.co.uk pages; can read page content.
  • content_scripts: https://at.liprock.com/* medium Script injected into unknown third-party domain at.liprock.com.

Pillar Scores

Permissions2.30
Reputation7.50
Network0.00
Webstore5.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn3af898f1dp727562726963xsx 4.35 Medium review 2026-08-26
v3.6 4.31 Medium review 2026-08-06

Bookkeeping

Rubric v3.6
Scored at 2026-08-06 05:35
Listing SHA 43ce163c21d1…
Force block — not fired
Score recovered no
Elapsed