Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

cjpalhdlnbpafiamejdnhcphjbkeiagm

cjpalhdlnbpafiamejdnhcphjbkeiagm
Risk Score
3.42
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Adblock
Installs
Rating
Last updated
Manifest version MV?
CSP present ❌ no
Developer
Verified publisher ❌ no
Featured by Google ❌ no
Web Store open ↗

Top Risks

  • Privacy policy is Google's generic policy (not scoped to uBlock), admits data collection and third-party sharing — score 10.0 on privacy pillar.
  • MV2 extension with webRequest+webRequestBlocking+<all_urls>: broad intercept capability on all traffic, though expected for adblock category.
  • Not a verified publisher; no Featured badge despite 11M installs — reduces reputation confidence.
  • MV2 manifest: Chrome is phasing out MV2 support, creating future compatibility uncertainty.
  • Privacy permission allows modification of browser-level privacy settings beyond typical adblock scope.

Evidence

  • privacy_policy_mismatch store Privacy URL is Google's generic account policy; scope_extension=false, data_collection=true, third_party_sharing=true — triggers +10 privacy pillar.
  • adblock_justified_discount manifest Category=Adblock; webRequest+<all_urls> match stated function; -1.5 justified-broad-permission discount applied.
  • manifest_version_mv2 manifest MV2 with no CSP remote hosts; CSP is strict ('self' only). v2 +2.0 Network for MV2+no-CSP does NOT apply — CSP is present.
  • no_bad_hosts crx threat_intel.bad_host_hits=[], monetization_hits=[], affiliate_hits=[]; no malicious or monetization network signals.
  • code_clean crx code_findings_raw=[]; obfuscation_score=0.0; 191 JS files scanned with no findings.
  • no_cves crx cve_findings_raw=[]; no vulnerable bundled libraries detected.
  • operator_cluster_clean api sibling_count=0; no related extensions sharing dev email or CSP host fingerprint.
  • no_verified_publisher store verified_publisher=false, is_featured_by_google=false; well-known open-source project but no store badge.

Permissions Breakdown

  • alarms low Used for periodic filter-list refresh scheduling.
  • contextMenus low Adds block-element right-click entries; minimal risk.
  • privacy high Allows modifying browser privacy settings (WebRTC, etc.).
  • storage low Stores filter lists and user settings locally.
  • tabs medium Reads tab URLs and titles; needed for per-tab blocking state.
  • unlimitedStorage low Required for large filter-list databases.
  • webNavigation medium Monitors navigation events to apply blocking rules.
  • webRequest high Intercepts all network requests; core adblock capability.
  • webRequestBlocking high Blocks requests synchronously; powerful but expected for adblock.
  • <all_urls> high Full host access on every site; necessary for universal blocking.

Pillar Scores

Permissions5.50
Reputation3.50
Network0.00
Webstore2.00
Maintenance0.00
Privacy10.00
Code Quality0.00
CVE Exposure0.00

Scoring History

sssiedn4b34c665dp727562726963xsx 3.27 Low review 2026-08-30
sssieddrubricxsx 3.41 Low review 2026-08-19
v3.6 3.42 Low review 2026-07-28
v1 3.73 Low review 2026-07-02

Bookkeeping

Rubric v3.6
Scored at 2026-07-28 17:39
Listing SHA 028e96ded571…
Force block — not fired
Score recovered no
Elapsed