Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Learn languages with Netflix & YouTube

cgelaojeiipaehoiiabkbickcpmpanel
Risk Score
4.91
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 9,000
Rating 3.8
Last updated 2025-09-01 (9 months ago)
Manifest version MV3
CSP present ❌ no
Developer Sergei.fedorenko.n@gmail.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy fetched but scope_extension==false AND data_collection+third_party_sharing==true → worst-case privacy score (10.0).
  • Brand impersonation: names YouTube and Netflix without verified ownership; developer is free-webmail gmail user with no dev name.
  • <all_urls> host_permissions + content_scripts on all URLs gives full DOM read/write on every site.
  • innerHTML DOM-XSS sink in options.dist.js with no CSP; elevated XSS risk.
  • No CSP on MV3 extension; dom_sink_innerhtml_userctrl risk is amplified per FIX B.

Evidence

  • brand_impersonation store brand_mention.is_impersonation=true; brands_mentioned=[youtube,netflix]; confirmed_owner=false; dev on gmail.
  • privacy_policy_scope_fail api policy fetched, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
  • all_urls_host_permission manifest <all_urls> in host_permissions + content_scripts_matches; category discount applies (-1.5) for TranslationTool.
  • dom_xss_sink_no_csp crx dom_sink_innerhtml_userctrl in options.dist.js; csp_present=false → +2.0 code quality (FIX B).
  • free_webmail_dev_no_name store developer_email=gmail.com, developer_name empty; floor triggers free-webmail+no-dev-name reputation risk.
  • verified_publisher store verified_publisher=true AND is_featured_by_google=true; applies reputation discounts.
  • months_since_update_6_12 store months_since_update=9 → maintenance +3.5 (6-12 month band).
  • cve_findings_empty crx cve_findings_raw=[]; CVE pillar=0.0.

Permissions Breakdown

  • tabs medium Can read tab URLs and metadata; moderate risk in language-learning context.
  • notifications low Push notifications only; low intrinsic risk.
  • storage low Local data persistence; standard for settings/vocabulary.
  • alarms low Scheduled execution; minimal risk alone.
  • <all_urls> (host_permissions) high <all_urls> host permission grants content script access to every site.
  • https://easy4learn.com/ (host_permissions) low Scoped to apparent dev backend domain.
  • https://elang.app/ (host_permissions) low Scoped to primary dev domain hosting the extension.
  • content_scripts <all_urls> high Content script injected on every page; broad DOM access.

Pillar Scores

Permissions5.50
Reputation5.50
Network2.00
Webstore4.50
Maintenance3.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA a007608b870b…
Force block — not fired
Score recovered no
Elapsed 26.4s