Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Clipboard History

cioiijhfebhhkmnijjjgbhkjjdlphjid
Risk Score
5.64
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 6,000
Rating 4.4
Last updated 2024-07-12 (23 months ago)
Manifest version MV3
CSP present ❌ no
Developer 2esengie2@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy — does not scope to this extension, admits data collection and 3rd-party sharing.
  • Install URL hijacks to developer's GitHub page; uninstall URL hijacks to Google Forms survey — both redirect users off-store.
  • Free-webmail developer (2esengie2@gmail.com) with no verified business identity, raising accountability concerns.
  • 23 months since last update — approaching stale threshold; React 16.13.1 bundled (no CVEs flagged but old version).
  • DOM innerHTML sink in React bundle without CSP — XSS risk if clipboard content ever routes to this sink.

Evidence

  • install_url_hijack store onInstalled opens tumutuk.github.io/clipboard-history/ — third-party GitHub page, not store listing.
  • uninstall_url_hijack store setUninstallURL points to forms.gle survey — third-party data collection on uninstall.
  • privacy_policy_generic store Policy URL is myaccount.google.com/privacypolicy — Google's own policy, not scoped to this extension.
  • free_webmail_developer store Developer email 2esengie2@gmail.com; no verified business domain; numbered alias pattern.
  • dom_sink_innerhtml_userctrl crx innerHTML assignment in assets/wall-1cf23f76.js; no CSP present — XSS sink unmitigated.
  • no_csp manifest content_security_policy is null on MV3 extension; default MV3 CSP applies but no custom hardening.
  • stale_maintenance store Last updated July 2024, 23 months ago — near 24mo high-risk threshold.
  • is_featured_by_google store Extension carries Google Featured badge, providing partial trust signal.

Permissions Breakdown

  • clipboardRead medium Reads all clipboard content; core function but sensitive — captures any copied data.
  • clipboardWrite medium Can overwrite clipboard; matches stated function but enables silent data replacement.
  • offscreen low Allows off-screen document for clipboard ops; low standalone risk.
  • storage low Local extension storage; needed to persist clipboard history.

Pillar Scores

Permissions2.00
Reputation7.50
Network2.00
Webstore7.50
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA c5450362d09b…
Force block — not fired
Score recovered no
Elapsed 23.5s