Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

YouNativefy

copobeiecgdaejfmkgadefmhhhbohike
Risk Score
4.33
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category TranslationTool
Installs 13
Rating 5.0
Last updated 2026-03-26 (5 months ago)
Manifest version MV3
CSP present ❌ no
Developer rafaelthiago01@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL returns fetch error — effectively no accessible privacy policy for 13-install extension contacting GCP backend.
  • Multiple innerHTML DOM-XSS sinks in content scripts on Netflix, Prime, YouTube without CSP to mitigate.
  • new Function() constructors in bundled node_modules (ajv, webpack) with no CSP — amplifies injection risk.
  • Brand impersonation signal: extension names/describes YouTube, Netflix, Disney+ without confirmed ownership.
  • Free-webmail dev email (gmail), no developer name disclosed; low accountability for backend data handling.

Evidence

  • privacy_policy_fetch_failed api privacy_policy_classification.fetched==false; HTTPError fetching https://younativefy.com.br/privacy → scored as no policy.
  • brand_impersonation store brand_mention: disney/youtube/netflix mentioned; confirmed_owner==false; is_impersonation==true.
  • dom_xss_no_csp crx 4 innerHTML sinks in content scripts + popup; csp_present==false; MV3 default CSP applies but no explicit extension CSP.
  • function_constructor_node_modules crx 6 new Function() hits in ajv, tapable, terser, webpack node_modules; likely build artifacts but bundled into CRX.
  • developer_identity_weak store developer_name empty; developer_email is free Gmail; no business domain verified.
  • backend_endpoint manifest host_permissions include younativefy-backend-800430356291.us-central1.run.app; data sent to GCP run app.
  • verified_publisher store verified_publisher==true; partially mitigates reputation risk but no featured badge.
  • low_install_count store Only 13 installs; operator_cluster sibling_count==0; limited blast radius but tail-attack surface.

Permissions Breakdown

  • activeTab low Scoped to user-initiated tab interaction only.
  • storage low Local data persistence; limited risk.
  • contextMenus low UI surface only; no data access.
  • host:youtube/netflix/disney+/max/amazon/primevideo medium Content scripts on major streaming platforms; broad but matches stated language-learning function.
  • host:younativefy-backend medium Calls dev-controlled backend; data sent to GCP endpoint without disclosed privacy policy.

Pillar Scores

Permissions2.50
Reputation6.00
Network2.50
Webstore3.00
Maintenance1.50
Privacy10.00
Code Quality4.50
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 10:31
Listing SHA d57028dd94dd…
Force block — not fired
Score recovered no
Elapsed