Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Vencord Web

cbghhgpcnddeihccjmnadmkaejncjndb
Risk Score
2.90
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Entertainment
Installs 200,000
Rating 4.3
Last updated 2026-05-08 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer tornike.khintibidze2@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail developer with no verified business identity and Discord brand impersonation flag.
  • host_permission to raw.githubusercontent.com enables fetching arbitrary remote scripts at runtime.
  • Privacy policy exists on vencord.dev but scope_extension==false; does not specify what this extension collects.
  • Featured by Google offsets but does not eliminate unverified individual developer risk at 200K installs.
  • declarativeNetRequest + Discord host access allows silent network-level manipulation of Discord traffic.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[discord]; confirmed_owner=false; dev domain is gmail.com.
  • free_webmail_developer manifest developer_email=tornike.khintibidze2@gmail.com; no business domain; domain_age_ct.queried=false.
  • github_raw_host_permission manifest host_permissions include https://raw.githubusercontent.com/* enabling remote code fetch from any public repo.
  • privacy_policy_scope_gap api privacy_policy_classification: fetched=true, scope_extension=false, data_collection=true, retention=true, third_party_sharing=false.
  • featured_by_google store is_featured_by_google=true; partially offsets reputation risk but does not confer verified-publisher status.
  • no_csp manifest content_security_policy=null; MV3 strict default applies, limiting but not eliminating remote-fetch risk.
  • clean_code_scan crx code_findings_raw=[], obfuscation_score=0.0, js_external_hosts=[], no eval/exfil patterns detected.
  • recently_updated store months_since_update=1; maintenance risk is minimal.

Permissions Breakdown

  • declarativeNetRequest medium Can block/redirect network requests; scoped to Discord domain via host_permissions.
  • *://*.discord.com/* medium Full access to Discord pages; content scripts injected here enabling DOM read/write.
  • https://raw.githubusercontent.com/* medium Can fetch arbitrary code from GitHub raw content — remote-code-loading risk surface.

Pillar Scores

Permissions3.50
Reputation7.50
Network2.00
Webstore4.50
Maintenance0.00
Privacy4.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA 1107444d0aa0…
Force block — not fired
Score recovered no
Elapsed 20.9s