Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Crypto Alert

cpclpigpkojganpmppallpfndknhmjmg
Risk Score
6.05
Risk Level: High
Recommendation: 🟠 HIGH RISK — review
Category Other
Installs 677
Rating 4.8
Last updated 2022-03-25
Manifest version MV3
CSP present ❌ no
Developer leonardodi1998@gmail.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Uninstall URL hijack redirects to SurveyMonkey — unsolicited data collection on removal.
  • Google privacy policy used as proxy — does not scope data handling to this extension at all.
  • 12 external JS hosts including polar-forest-22938.herokuapp.com (ephemeral server) and track.youhodler.com (tracking).
  • Last updated March 2022 (38 months ago) — abandoned with no security patches.
  • No CSP + DOM innerHTML sinks from external API data expose XSS risk from any compromised upstream host.

Evidence

  • uninstall_url_hijack crx chrome.runtime.setUninstallURL points to it.surveymonkey.com/r/WZ5786N — 3rd-party redirect on removal.
  • generic_privacy_policy store Privacy policy is Google's own account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • abandoned_extension store Last updated March 25, 2022 — 38 months without update; maintenance score maxed.
  • external_hosts_broad crx 12 distinct external hosts including herokuapp.com ephemeral server and track.youhodler.com tracker.
  • no_csp manifest content_security_policy is null — no CSP on MV3 extension; amplifies DOM-XSS risk.
  • free_webmail_developer store Developer email is leonardodi1998@gmail.com with no business domain or verified publisher status.
  • dom_xss_sinks crx Two innerHTML assignments from variables in popup.js and provaJSON.js without sanitization.
  • geo_diversity crx JS hosts span 4 countries (CA, DE, IN, US) — elevated supply-chain attack surface.

Permissions Breakdown

  • notifications medium Used for price alerts; medium risk when combined with alarms.
  • alarms low Schedules periodic checks; low intrinsic risk.
  • storage low Stores user preferences locally; low risk.

Pillar Scores

Permissions1.30
Reputation6.50
Network5.50
Webstore6.00
Maintenance10.00
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 05:58
Listing SHA 0d20bc11deec…
Force block — not fired
Score recovered no
Elapsed 21.9s