Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Orion NFT

chifiemgnomlmdcnfelomkihkeapkedi
Risk Score
5.53
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Other
Installs 30
Rating
Last updated 2022-07-30 (47 months ago)
Manifest version MV3
CSP present ❌ no
Developer launay.tug@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extension last updated ~34 months ago — deeply stale, no maintenance signal.
  • Privacy policy is Google's generic account policy, not scoped to this extension; admits data collection and 3rd-party sharing.
  • Free-webmail developer (gmail.com) with no verified business identity or domain.
  • No CSP defined; innerHTML sink in content script creates DOM-XSS risk on OpenSea/Etherscan pages.
  • Very low install count (30) with stale MV3 and no ratings — limited community vetting.

Evidence

  • developer_email_free_webmail store Developer email launay.tug@gmail.com; no business website or verified publisher.
  • privacy_policy_generic_google store Policy URL is myaccount.google.com — Google's own policy, not scoped to this extension.
  • privacy_policy_classification api fetched=true, scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy.
  • maintenance_stale store Last updated July 2022 (~34 months); +8.5 maintenance penalty.
  • no_csp manifest content_security_policy is null; no CSP present on MV3 extension with innerHTML sink.
  • dom_sink_innerhtml_userctrl crx content-scripts/main.js assigns innerHTML from variable — potential DOM-XSS on etherscan/opensea pages.
  • js_external_hosts crx Contacts api.opensea.io, opensea.io, github.com — 3 external hosts, consistent with stated NFT function.
  • low_installs_stale store Only 30 installs, 0 ratings, no community validation, deeply stale.

Permissions Breakdown

  • content_scripts: https://etherscan.io/address/* medium Injects JS into etherscan address pages; can read page content and DOM.
  • content_scripts: https://opensea.io/collection/* medium Injects JS into OpenSea collection pages; can read and modify page content.

Pillar Scores

Permissions0.30
Reputation6.50
Network0.00
Webstore10.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 05:57
Listing SHA 6d5a37f966c8…
Force block — not fired
Score recovered no
Elapsed 20.8s