Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MultiPassword — Password manager

cnlhokffphohmfcddnibpohmkdfafdli
Risk Score
3.55
Risk Level: Low
Recommendation: 🟢 LOW RISK — review
Category Security
Installs 1,000,000
Rating 4.8
Last updated 2026-03-04 (3 months ago)
Manifest version MV3
CSP present ✅ yes
Developer info@multipassword.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Broad host access (https://*/*, http://*/*) combined with webRequest and scripting allows full page interception on every site.
  • browsingData + privacy permissions grant destructive browser-state control beyond typical password manager needs.
  • Privacy policy not scoped to this extension; data_collection=false but scope_extension=false — policy doesn't cover extension behavior.
  • sandbox CSP contains unsafe-inline and unsafe-eval, weakening XSS mitigations in sandboxed pages.
  • Three innerHTML DOM-XSS sinks in injected content scripts could be exploited if attacker-controlled data reaches them.

Evidence

  • verified_publisher+featured store Extension has Google verified publisher badge and is featured — strong trust signal; reputation floored at 2.0.
  • broad_host_access manifest host_permissions: https://*/*, http://*/* — full site access; justified-broad discount applied for PasswordManager category.
  • sandbox_csp_unsafe manifest sandbox CSP includes unsafe-inline and unsafe-eval on script-src, weakening XSS defenses in sandboxed contexts.
  • privacy_policy_not_scoped api privacy_policy_classification: fetched=true, scope_extension=false, data_collection=false → +9.0 privacy pillar.
  • dom_xss_sinks crx 3 innerHTML DOM-XSS sinks found in chunks and injectContent; csp_present=true limits upgrade to +2.0 total.
  • geo_diversity crx JS external hosts span 5 countries (CA,IN,NL,SG,US); +1.5 network for category not in VPN/Antivirus/etc.
  • no_cve_findings crx cve_findings_raw is empty; CVE pillar = 0.0.
  • recently_updated store Last updated March 4 2026, months_since_update=3; maintenance pillar = 0.0.

Permissions Breakdown

  • unlimitedStorage low Expected for password manager storing vault data locally.
  • privacy high Can modify browser privacy settings; HIGH-tier permission.
  • activeTab low Limited to currently active tab on user action.
  • browsingData high Can delete cookies, history, cache — significant data-erasure capability.
  • clipboardWrite medium Needed for copy-password functionality; write-only.
  • contextMenus low UI surface only; low risk.
  • scripting medium Can inject scripts into pages; combined with broad host access is elevated.
  • storage low Standard extension storage for settings/vault references.
  • tabs medium Can read tab URLs and titles; moderate privacy exposure.
  • offscreen low Used for background DOM operations; low standalone risk.
  • webRequest high Can observe all network requests; significant surveillance capability.
  • https://*/* high Broad host access across all HTTPS sites amplifies scripting+webRequest risk.
  • http://*/* high Broad host access across all HTTP sites.

Pillar Scores

Permissions5.50
Reputation2.00
Network2.50
Webstore2.00
Maintenance0.00
Privacy9.00
Code Quality2.00
CVE Exposure0.00

Scoring History

v3.6 3.55 Low review 2026-06-16
v3.4-rev 3.47 Low review 2026-06-15

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:24
Listing SHA 8a7957ecfa48…
Force block — not fired
Score recovered no
Elapsed 32.8s