Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Image downloader - picture and photos saver

cbnhnlbagkabdnaoedjdfpbfmkcofbcl
Risk Score
4.18
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category MediaDownloader
Installs 100,000
Rating 4.8
Last updated 2025-01-22 (18 months ago)
Manifest version MV3
CSP present ❌ no
Developer hagelakimosy@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host permissions (<all_urls>, http://*/* , https://*/*) combined with webRequest on MV3 — can observe all browsing traffic.
  • Gmail developer with no verified business identity; free-webmail dev raises accountability concerns.
  • No CSP defined; DOM-XSS innerHTML sink in popup JS increases XSS risk if page content is unsanitized.
  • Privacy policy hosted on Google Sites free hosting, lacks data retention disclosure.
  • 17 months since last update approaches stale threshold; no changelog visible.

Evidence

  • broad_host_permissions manifest host_permissions include http://*/*, https://*/*, <all_urls> — full browsing reach.
  • webRequest_broad manifest webRequest declared alongside <all_urls>; can observe all network activity.
  • free_webmail_dev store Developer email hagelakimosy@gmail.com; no verified business domain.
  • no_csp crx content_security_policy is null; MV3 default applies but no hardened policy set.
  • dom_xss_sink crx innerHTML assignment in popup/index.js — potential DOM-XSS if input unsanitized.
  • privacy_policy_free_hosting store Policy on Google Sites free hosting; no retention clause; third_party_silence=true.
  • is_featured_by_google store Extension carries Google Featured badge, partially offsetting reputation concerns.
  • stale_17mo store Last updated January 2025; 17 months since update, approaching high-risk staleness band.

Permissions Breakdown

  • storage low Stores user preferences; minimal risk.
  • activeTab medium Access to current tab on user action; scoped but non-trivial.
  • scripting medium Can inject scripts into pages; elevated with broad host access.
  • downloads medium Can save files to disk; core to stated function but abusable.
  • webRequest high Intercept/observe all network requests across all URLs.
  • declarativeNetRequest medium Can block/redirect requests declaratively; lower risk than webRequest.
  • http://*/* high Broad host access to all HTTP sites.
  • https://*/* high Broad host access to all HTTPS sites.
  • <all_urls> high Redundant with above; grants access to every URL including chrome-extension.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore2.50
Maintenance3.50
Privacy2.00
Code Quality2.00
CVE Exposure0.00

Scoring History

sssieddrubricxsx 5.17 Medium review 2026-07-31
v3.6 4.18 Medium review 2026-06-16

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:22
Listing SHA 7f8c4a5d329d…
Force block — not fired
Score recovered no
Elapsed 24.7s