Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Rakuten: Get Cash Back For Shopping

chhjbpecpncaggjpdakmflnfcopglcmi
Risk Score
3.68
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Shopping
Installs 3,000,000
Rating 4.9
Last updated 2026-07-27 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer cashbackbutton@rakuten.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is generic corporate policy (scope_extension=false) admitting data collection and third-party sharing — worst-case privacy score triggered.
  • cookies + <all_urls> + webRequest combination allows broad sitewide cookie read/write and request interception.
  • scripting + <all_urls> enables arbitrary JS injection on every visited page.
  • No CSP present (MV3 provides some default protection but no explicit scope restriction).
  • new Function() constructor in bg.js enables dynamic code execution; low obfuscation but warrants review.

Evidence

  • verified_publisher + featured store Rakuten is a verified publisher with Google Featured badge; reputation floored at 2.0.
  • privacy_policy_scope_mismatch api Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy (v3.5 D).
  • cookies + <all_urls> manifest HIGH permission pair; ×1.2 amplifier applied on permissions pillar.
  • function_constructor in bg.js crx new Function() found; +2.5 code quality per debugger_attach/function_constructor rule.
  • 7 external JS hosts crx button.rrcbsn.com, capture.ecbsn.com, cas.rrcbsn.com, search.ecbsn.com + app stores contacted.
  • no bad_host_hits / affiliate_hits / monetization_hits api Threat intel clean; no ad-tech or affiliate network hits detected.
  • 3M installs, rating 4.9, zero review red flags store High install count with strong rating and no malware/redirect complaints in reviews.
  • justified-broad-permission discount applied manifest Shopping/cashback category matches broad host access; -1.5 discount on permissions pillar.

Permissions Breakdown

  • tabs medium Can read tab URLs and titles across all navigation events.
  • webNavigation medium Observes all navigation events; needed for cashback trigger detection.
  • webRequest high Intercepts all HTTP requests across all URLs — high surveillance capability.
  • storage low Stores extension state locally; standard low risk.
  • cookies high Combined with <all_urls> allows reading/writing cookies sitewide — ×1.2 amplifier applies.
  • alarms low Schedules background tasks; low standalone risk.
  • scripting high Programmatic script injection into pages; paired with <all_urls> is broad capability.
  • <all_urls> (host_permission) high Grants access to every origin; justified by cashback category but amplifies cookies+webRequest.

Pillar Scores

Permissions4.50
Reputation2.00
Network3.50
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality2.50
CVE Exposure0.00

Scoring History

xx pfsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.51 Low review 2026-08-09
%22fsssiedxa sssiedx 4.12 Medium review 2026-08-09
%27fsssiedxa$'sssiedx 4.02 Medium review 2026-08-09
4.08 Medium review 2026-08-09
$"fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.78 Low review 2026-08-09
fsssiedxa$"sssiedx 3.73 Low review 2026-08-09
<fsssiedxi xx psssiedx 3.61 Low review 2026-08-08
<fsssiedxi$"sssiedx 4.27 Medium review 2026-08-08
<fsssiedxa xx psssiedx 3.69 Low review 2026-08-03
<fsssiedxa&#x22;sssiedx 3.74 Low review 2026-08-03
<fsssiedxifdsaxax><!--></ScRiPt>asddsssiedx 2.81 Low review 2026-08-03
<fsssiedxi'sssiedx 4.34 Medium review 2026-08-03
fsssiedx<sssiedx 2.59 Low review 2026-08-03
<fsssiedxa"sssiedx 3.77 Low review 2026-08-02
<fsssiedxa$'sssiedx 3.58 Low review 2026-08-02
<fsssiedxa'sssiedx 3.67 Low review 2026-08-02
<fsssiedxa$"sssiedx 3.68 Low review 2026-08-02
<fsssiedxafdsaxax><!--></ScRiPt>asddsssiedx 3.69 Low review 2026-08-02
<fsssiedxa&#x27;sssiedx 4.07 Medium review 2026-08-02
fsssiedxa<sssiedx 3.39 Low review 2026-08-02
sssieddrubricxsx 3.99 Low review 2026-07-31
v3.6 3.68 Low review 2026-06-16
v3.4-rev 4.67 Medium review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA b27491502a1c…
Force block — not fired
Score recovered no
Elapsed 26.8s