Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Weather Widget

cbfonhkeidkoldmfnffmpejogimdjknc
Risk Score
3.38
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Other
Installs 111
Rating 5.0
Last updated 2025-08-21 (10 months ago)
Manifest version MV3
CSP present ❌ no
Developer rohanbpatil77@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Content script declared on <all_urls> runs on every page despite no other permissions declared.
  • Developer uses free Gmail address with no verified business identity.
  • Privacy policy is only 160 chars, hosted on free GitHub Pages, lacks retention disclosure.
  • No CSP declared (MV3 default applies, but adds no extra hardening signal).
  • jquery 3.5.1 bundled — minor known CVEs exist in older patch levels; no code findings detected.

Evidence

  • content_scripts_matches:<all_urls> manifest Content script injected on all URLs; broad site reach with no declared permission guards.
  • gmail_developer store Developer email rohanbpatil77@gmail.com is free webmail; no business domain verified.
  • privacy_policy_very_short crx Policy fetched but only 160 chars; scope_extension=true, data_collection=true, retention=false.
  • third_party_silence api Privacy policy does not mention third-party data sharing (+1.0 to privacy pillar).
  • jquery_3.5.1_bundled crx jquery 3.5.1 detected; no CVEs flagged in cve_findings_raw but version is not fully patched.
  • single_external_host crx Only api.openweathermap.org contacted; consistent with stated weather widget function.
  • is_featured_by_google store Extension carries Google Featured badge, partial trust signal.
  • maintenance_6_12mo store Last updated August 2025; ~10 months ago — moderate staleness tier.

Permissions Breakdown

  • content_scripts:<all_urls> high Content script injected on every site visited; broad reach despite no declared permissions.

Pillar Scores

Permissions3.50
Reputation6.50
Network2.00
Webstore1.50
Maintenance3.50
Privacy2.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA 1cde4f7c513b…
Force block — not fired
Score recovered no
Elapsed 17.9s