Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Virtual Json Viewer

cipnpfcceoapeahdgomheoecidglopld
Risk Score
2.77
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category DeveloperTools
Installs 3,000
Rating 4.7
Last updated 2026-06-03
Manifest version MV3
CSP present ❌ no
Developer paolo.simone.dev@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • <all_urls> content script gives access to every page the user visits, including sensitive web apps.
  • Developer email is free webmail (gmail.com) with no verifiable business identity.
  • Privacy policy is 130-char GitHub raw text; scope_extension==false, retention not disclosed.
  • No CSP defined (MV3 mitigates somewhat but adds no explicit script restriction).
  • Unverified individual developer; no featured/verified-publisher badge reduces accountability.

Evidence

  • broad_host_access manifest host_permissions and content_scripts_matches both contain <all_urls>; injected into every site.
  • no_csp manifest content_security_policy is null; MV3 default applies but no explicit hardening.
  • free_webmail_dev store Developer email paolo.simone.dev@gmail.com; no verified business domain.
  • privacy_policy_thin api Policy fetched (130 chars); scope_extension=false, data_collection=false, retention=false.
  • clean_code_scan crx code_findings_raw empty, obfuscation_score=0.0, js_external_hosts empty — no malicious indicators.
  • no_cve crx cve_findings_raw empty; no known-vulnerable bundled libraries detected.
  • featured_by_google store is_featured_by_google=true; follows recommended practices per Web Store.
  • justified_broad_host manifest DeveloperTools JSON viewer requires <all_urls> to reformat JSON responses on any domain.

Permissions Breakdown

  • storage low Stores extension settings locally; no user-data exfil risk on its own.
  • <all_urls> (host_permissions) high Content script injected into every page; can read/modify any page content.
  • <all_urls> (content_scripts_matches) high Confirms broad injection scope; same surface as host_permissions — counted once.

Pillar Scores

Permissions3.50
Reputation6.50
Network0.00
Webstore0.00
Maintenance0.00
Privacy9.00
Code Quality0.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:23
Listing SHA 9a93da7208bd…
Force block — not fired
Score recovered no
Elapsed 19.6s