Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Productivity Blocker

cfbhoifjdjphbjcjmkpilkdeplfomjbn
Risk Score
6.45
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Productivity
Installs 236
Rating 5.0
Last updated 2022-12-29 (44 months ago)
Manifest version MV3
CSP present ❌ no
Developer productivityblocker@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Abandoned 42 months ago — well past 36mo threshold; zombie extension with broad host access.
  • Privacy policy is generic Google account policy — not scoped to this extension; admits data collection and 3rd-party sharing.
  • Free-webmail (gmail) developer with no verified business identity raises accountability concerns.
  • Broad host permissions (https://*/* + http://*/) grant access to all sites despite small install base (247 users).
  • External JS hosts (raw.githubusercontent.com, productivityblocker.com) without CSP — remote code loading risk unmitigated.

Evidence

  • stale_extension store Last updated December 29 2022; 42 months since update triggers +10.0 maintenance score.
  • generic_privacy_policy store PP is Google account policy (scope_extension=false, data_collection=true, third_party_sharing=true) → +10.0 privacy per v3.5 rule D.
  • free_webmail_developer manifest Developer email productivityblocker@gmail.com; no verified business; reputation starts at 5.0 +1.5 webmail.
  • broad_host_permissions manifest https://*/* and http://*/* grant access to all sites; paired with declarativeNetRequest.
  • external_js_hosts crx raw.githubusercontent.com and www.productivityblocker.com listed as external hosts; no CSP to constrain them.
  • no_csp manifest content_security_policy is null; MV3 has strict default but external hosts increase risk.
  • install_perm_anomaly api 247 installs with high-tier host permissions flagged as small_install_high_perm=true, tail_attack_surface=true.
  • featured_by_google store is_featured_by_google=true provides moderate reputation credit (-2.0 featured discount applied).

Permissions Breakdown

  • storage low Local data persistence; low standalone risk.
  • alarms low Scheduled tasks; minimal risk.
  • declarativeNetRequest medium Can block/redirect network requests; fits blocker category.
  • https://*/* high Broad HTTPS host access across all sites.
  • http://*/* high Broad HTTP host access across all sites.

Pillar Scores

Permissions4.50
Reputation7.00
Network4.00
Webstore5.50
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

<fsssiedx{"sssiedx 6.72 High review 2026-08-24
fsssiedx<sssiedx 6.39 High review 2026-08-24
%22fsssiedxefdsaxax><!--></ScRiPt>asddsssiedx 6.18 High review 2026-08-24
%27fsssiedxe sssiedx 6.44 High review 2026-08-24
&#x27;fsssiedxe sssiedx 6.27 High review 2026-08-24
6.53 High review 2026-08-24
fsssiedxe<sssiedx 6.73 High review 2026-08-24
fsssiedxa"sssiedx 6.23 High review 2026-08-20
sssieddrubricxsx 6.84 High review 2026-08-20
v3.6 6.45 High review 2026-06-16
v3.4-rev 6.10 High review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA 5818372f4efe…
Force block — not fired
Score recovered no
Elapsed 21.5s