Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

JSON Formatter

cigpimdanlhjegpobmgjpkpmcileefee
Risk Score
5.13
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 331
Rating
Last updated 2022-10-28 (44 months ago)
Manifest version MV3
CSP present ❌ no
Developer info@linangdata.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Extension not updated in 44 months — stale and potentially abandoned.
  • Privacy policy URL returns HTTP error; policy effectively inaccessible and unverifiable.
  • No developer name listed; only email on a small-footprint domain.
  • jquery 3.5.1 bundled with no CSP — minor DOM-sink exposure without policy enforcement.
  • JS external hosts include getbootstrap.com, popper.js.org, github.com — external resource references though no remote loading detected.

Evidence

  • maintenance_stale store Last updated October 2022; 44 months since update triggers maximum maintenance score (10.0).
  • privacy_policy_fetch_failed api privacy_policy_classification.fetched=false (fetch_error:HTTPError); policy URL exists but unreachable — scored as no policy (+10.0).
  • no_developer_name store developer_name is empty string; only email info@linangdata.com available.
  • verified_publisher store verified_publisher=true; applies -3.0 reputation discount (floor 2.0).
  • jquery_3_5_1_no_csp crx jquery@3.5.1 bundled; no CSP present. v2 rule: jquery<3.5 + no CSP +2.0 code quality — version is 3.5.1 so threshold not met; no CVEs found.
  • cve_findings_empty crx cve_findings_raw=[]; no CVE exposure found for bundled libraries.
  • js_external_hosts crx 4 external JS hosts: getbootstrap.com, github.com, linangdata.com, popper.js.org. No bad-host or monetization hits.
  • obfuscation_none crx obfuscation_score=0.0; code_findings_raw=[]; no malicious indicators detected.

Permissions Breakdown

  • clipboardRead medium Can read clipboard contents; relevant for JSON paste workflow but sensitive.
  • clipboardWrite medium Can write to clipboard; paired with Read for format-and-copy workflow.
  • contextMenus low Adds right-click menu entries; minimal risk.

Pillar Scores

Permissions2.00
Reputation4.00
Network1.50
Webstore0.00
Maintenance10.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA ed414b62aaf7…
Force block — not fired
Score recovered no
Elapsed 19.3s