Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

FlySafe - Avoid Boeing Flights

chbkdaaihckneklhbadanlnoimmlhkii
Risk Score
5.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 7
Rating
Last updated 2025-06-13 (13 months ago)
Manifest version MV3
CSP present ❌ no
Developer petro.90@hotmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • <all_urls> content script on every site with innerHTML DOM-XSS sink in content.js
  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing
  • No developer name; free-webmail hotmail dev with no business domain or identity verification
  • Only 7 installs but carries HIGH-tier host permission — tail attack surface anomaly flagged
  • Verified-publisher badge offers limited assurance given generic privacy policy and anonymous dev identity

Evidence

  • host_permissions=<all_urls> + content_scripts on all URLs manifest Extension injects content script on every site; maximum DOM read/write reach.
  • dom_sink_innerhtml_userctrl in content.js crx innerHTML assigned from variable replacedText — DOM-XSS risk on all pages visited.
  • privacy_policy is Google generic policy store URL is myaccount.google.com/privacypolicy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • developer identity store No developer name; email petro.90@hotmail.com (free webmail, numbered alias pattern).
  • install_perm_anomaly api 7 installs with HIGH-tier host permission; small_install_high_perm=true, tail_attack_surface=true.
  • verified_publisher=true store Verified publisher badge present but generic policy and anonymous dev limit its assurance value.
  • maintenance: 13 months since update store Last updated June 13 2025; 12-24mo band → +6.0 maintenance score.
  • csp_present=false, MV3 manifest No CSP declared; MV3 strict default applies so no +2.0 network penalty.

Permissions Breakdown

  • <all_urls> (host_permissions) high Grants content script access to every site the user visits — maximum reach.
  • <all_urls> (content_scripts_matches) high Content script injected on all URLs; can read/modify any page DOM.

Pillar Scores

Permissions6.00
Reputation6.50
Network2.00
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-07-08 14:28
Listing SHA b1db2a38abab…
Force block — not fired
Score recovered no
Elapsed