Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Paint Online - Drawing Tool

cclhgechkjghfaoebihpklmllnnlnbdb
Risk Score
5.18
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 50,000
Rating 4.5
Last updated 2024-08-05 (24 months ago)
Manifest version MV3
CSP present ❌ no
Developer samkovvaiva33@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Gmail developer with no verified domain; free-webmail identity is unaccountable long-term.
  • Privacy policy is Google's own generic policy — does not scope to this extension at all (D-rule: data_collection+third_party_sharing without scope → +10.0).
  • Extension is 24 months stale with broad *://*/* host permission and scripting — supply-chain risk window.
  • No CSP on MV3 extension is unusual; no observable code surface makes audit harder.
  • External JS hosts (jquery.org, sizzlejs.com, vanilla-picker.js.org, github.com) noted in manifest but code findings empty — sourcing cannot be fully verified.

Evidence

  • broad_host_permission manifest *://*/* host permission paired with scripting API — can inject code into any site the user visits.
  • generic_privacy_policy store Policy URL is Google's own account privacy page; scope_extension=false, data_collection=true, third_party_sharing=true → D-rule +10.0.
  • free_webmail_developer store Developer email samkovvaiva33@gmail.com; no verified publisher, no business domain, gmail identity.
  • stale_extension store Last updated August 2024; 24 months since update → Maintenance +6.0.
  • no_csp manifest content_security_policy is null; csp_present=false on MV3 extension with external JS hosts referenced.
  • external_js_hosts crx js_external_hosts: github.com, jquery.org, sizzlejs.com, vanilla-picker.js.org — no bad-host hits found.
  • is_featured_by_google store Extension carries Google Featured badge — partial trust signal offsetting reputation slightly.
  • no_code_findings crx obfuscation_score=0.0, code_findings_raw empty, 6 JS files scanned — no active malicious signals detected.

Permissions Breakdown

  • storage low Stores local drawing state; low risk.
  • activeTab medium Accesses current tab on user gesture; moderate but bounded risk.
  • scripting medium Can inject scripts into pages; elevated when paired with broad host_permissions.
  • *://*/* (host_permission) high Broad host access across all URLs amplifies scripting and activeTab risk significantly.

Pillar Scores

Permissions5.50
Reputation6.50
Network2.00
Webstore2.00
Maintenance6.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 07:48
Listing SHA ef5f52c0ef83…
Force block — not fired
Score recovered no
Elapsed